Revolut confirms customer data breach through fake government requests — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Revut confirmed it handed sensitive customer data to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain, in what it called a "sophisticated external impersonation scam."
- The exposed data included birth dates, postal and email addresses, phone numbers, and copies of identity documents like passports and driver's licenses; verification selfies, account statements, and transaction histories may also have been compromised.
- Revolut said a "limited" number of customers were affected but declined to disclose the exact count, the affected market, or which government agency was involved, though it blocked the email address and alerted law enforcement and regulators.
- Crypto security researcher ZachXBT posted about the breach late Friday and said the incident appeared to have targeted high-net-worth users.
- Revolut told customers its systems and customer funds are unaffected; the London-based fintech has 80 million-plus customers globally and operates as a bank in more than 30 countries.
- The disclosure comes as Revolut received conditional U.S. OCC approval earlier this month to launch a national bank in H1 2027 and is reportedly weighing an IPO that could value it at up to $200 billion, up from a $75 billion private valuation in November.
Why it matters: The breach — which reportedly targeted Revolut's wealthiest users and exposed identity documents and biometric data — lands as the fintech pushes into U.S. banking via an OCC-approved national charter targeted for H1 2027. Even though Revolut insists funds and core systems remain unaffected, the incident will draw regulatory attention at a moment when the company is pitching investors on a potential $200 billion IPO.
Ask SkimNews




