Revolut has acknowledged that it handed sensitive customer records to an unauthorized party after an impersonation scam, the company's disclosure states. The London-based banking and financial platform, which serves more than 80 million customers worldwide, says the incident was an external impersonation scam rather than a breach of its own systems. Customer funds were not affected, according to the company.
The attacker appears to have leaned on the credibility of a genuine government email domain, and Revolut has not named the agency involved or revealed the domain. Revolut says it spotted the activity, blocked the sending address, and alerted the government agency involved along with law enforcement, data protection and financial regulators. In a statement, Revolut said: "Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators."
The records were obtained through social engineering rather than any access to Revolut's systems. What was exposed includes dates of birth, postal addresses, email addresses and phone numbers, plus copies of passports and driver's licenses. Verification selfies, account statements and transaction histories were also among the data disclosed.
Revolut describes the number of customers caught up in the incident as limited or very limited, and says it has contacted those affected directly. Each of those customers is receiving an email that spells out which pieces of their personal data were disclosed. The company has not put a figure on how many customers were affected.
Malwarebytes Labs, which wrote up the incident, expects the fallout to arrive as follow-on fraud attempts instead of money leaving accounts right away, and it urges readers to treat any surprise message about a Revolut account as a likely scam. Revolut advises cutting off any exchange with a suspected scammer and getting in touch only through its own official routes, while Malwarebytes Labs says unfamiliar activity should be reported in the secure in-app chat Revolut runs.
The disclosure lands in a stretch of scam and malware reporting that has repeatedly centered on trusted brands and communication channels. Earlier this month, the email marketing provider Brevo initially reported that an intruder had reached 120 customer accounts, with some of them used to phish crypto newsletter subscribers. Separate research described an Android Trojan called Gigabud that builds a work profile on a device and clones a banking app inside it. Reporting has also traced how loyalty points fraud helps fund hacker activity.
What the Revolut case does not settle is how the impersonation was pulled off at the domain level, or which government body the attacker was pretending to represent. The company's account leaves both questions open while its notification effort continues.













