Revolut leaks customer data after fraudulent government-domain requests

Revolut disclosed that an unauthorized third party obtained sensitive customer information by sending fraudulent requests from a legitimate government email domain. Exposed data included identity documents, contact details, and transaction histories. The company said it has notified affected customers and alerted authorities.
The breach involved fraudulent requests sent from a legitimate government email domain, a technique that exploits trust in official channels. Revolut has not disclosed the number of affected customers, the specific market involved, or the government agency whose domain was misused. The company confirmed it blocked the address and alerted regulators, law enforcement, and the relevant agency.
The incident arrives during a period of significant growth for the fintech, which serves over 80 million customers globally and recently secured conditional U.S. approval to establish a national bank. Security researcher ZachXBT suggested the attack may have targeted high-net-worth individuals. Revolut is reportedly weighing a public listing that could value the company at up to $200 billion.
This incident could erode trust in digital-only banking platforms that hold sensitive identity data, particularly among high-value customers who may reconsider their reliance on such services. The use of a legitimate government domain in the attack may also raise broader concerns about the security of official communication channels, potentially affecting how individuals verify authenticity of government correspondence. Affected customers could face heightened risks of identity theft or fraud, and the wider fintech industry may need to reassess verification protocols.