The Wire
BusinessTechnologyCybersecurityWorld

Revolut says fake government requests exposed customer data

Revolut says fake government requests exposed customer data
Photo: techcrunch.com

Revolut disclosed that fraudulent government-style requests exposed customer data.

Why it matters: The incident shows how impersonation can slip through compliance workflows at a major fintech. It also raises privacy and regulator-notification issues for a bank-like app handling sensitive identity data.

  • Revolut said an unauthorized third party used a legitimate government-agency email domain to submit fraudulent requests for information.
  • The company said the incident affected a limited number of customers, but it did not say how many or identify the government agency.
  • Revolut said it blocked the email address used in the impersonation attempt and notified customers, regulators, law enforcement and the relevant government agency.
  • The exposed records included birth dates, postal and email addresses, phone numbers, and copies of passports and driver’s licenses.

Revolut said on Feb. 18, 2025, that it had disclosed customer information after what it described as a sophisticated external impersonation scam. In a statement quoted by TechCrunch, a spokesperson said an unauthorized third party used a legitimate government-agency email domain to submit fraudulent requests for information. Revolut said its systems and customer funds were not affected.

The company said the incident affected a limited number of customers, but it did not say how many or identify the government agency involved. Reuters reported, in a story republished by CNA, that Revolut alerted data protection and financial regulators as well as law-enforcement agencies after the disclosure.

Revolut said the exposed records included identity and contact details such as birth dates, postal and email addresses, phone numbers, and copies of identity documents including passports and driver’s licenses. TechCrunch also reported that the data may have included verification selfies, account statements and transaction histories, but Revolut did not confirm those details in the statement cited in the article.

The company said it blocked the email address used in the impersonation attempt. It has not said which markets were affected.

By the numbers

  • Feb. 18, 2025 - Revolut disclosed the incident.
  • Limited number of customers - Revolut said the exposure affected only a limited group, but did not give a count.

Yes, but: Revolut has not said how many customers were affected or which government agency was impersonated, and some reported details were not confirmed by the company.

Based on reporting from

  • TechCrunch

See how this story touches your network - open The Wire in Jane.

Open in Jane