Revolut leaks customer data after phishing scam impersonating government agency

Revolut disclosed a data breach after an attacker posing as a government agency tricked the fintech into sharing customer information. The exposed data includes identity documents, contact details, account statements, and transaction histories for a limited number of customers. Revolut says systems and funds were unaffected and has alerted regulators and law enforcement.
The breach was executed through a sophisticated social engineering attack: the actor used a legitimate government email domain with valid authentication, making the request appear authentic. Revolut fulfilled it under that reasonable belief, highlighting how even verified domains can be abused. The exposed data is highly sensitive, including identity documents, facial verification images, and full transaction histories, which could enable identity theft or targeted fraud.
This incident follows a 2022 breach that affected 50,150 customers, suggesting recurring vulnerabilities in Revolut’s data-handling processes. While the company states systems and funds were unaffected, the targeted nature—possibly aimed at high net worth individuals per crypto investigator ZachXBT—raises concerns about the value of the stolen information. Revolut has alerted regulators and law enforcement but has not disclosed the exact number of victims.
This breach could erode trust in digital-first financial services, especially among high-net-worth users who may become prime targets for sophisticated phishing. The exposure of identity documents and facial verification data may enable long-term identity fraud, affecting victims beyond financial loss. It also underscores that even regulated fintechs can be deceived by convincing impersonation, potentially prompting stricter verification protocols across the industry. Customers may face increased phishing risks as stolen data is weaponized, though Revolut’s swift response may mitigate broader systemic impact.