Financial technology and banking firm Revolut disclosed that sensitive customer data, including passport copies, verification selfies and full transaction histories, was released after a fraudulent request appeared to come from a government agency.
According to a post by International Cyber Digest on X, requests for customer information sent from a legitimate government agency email domain passed Revolut’s authentication checks. Revolut later concluded the requests were not authentic and said customers whose information was compromised were notified on Friday.
A company spokesperson told Cointelegraph on Saturday that Revolut identified a sophisticated external impersonation scam in which an unauthorised third party used a legitimate government agency domain email to submit fraudulent information requests. The spokesperson said Revolut blocked the address after detection, alerted the relevant government agency and notified enforcement agencies and financial regulators.
The spokesperson added that Revolut systems and customer funds were unaffected and that the company contacted the limited number of impacted individuals directly. ZachXBT, a crypto sleuth, reportedly said the incident appeared limited in size and aimed at high-net-worth users.
The incident prompted criticism on X of mandatory information-sharing requirements. One user, Marc Zeller, said he woke to find his data leaked by Revolut and wrote that KYC had not produced meaningful upside and had put many people in harm’s way.













