Revolut gave customer IDs and financial data to a government impostor
Revolut handed customer IDs, selfies, and financial records to criminals using a legitimate government agency email domain.
Revolut acknowledged disclosing sensitive customer records after accepting fraudulent information requests sent from an email address on a legitimate government agency domain, describing it as an external impersonation scam rather than a system intrusion. The London-based fintech, which serves more than 80 million customers globally, says customer funds were not affected and only a 'very limited' number of customers were impacted. Disclosed data includes identity and contact information, copies of passports and driver's licenses, verification selfies, account statements, and transaction histories. Revolut blocked the sending address and notified the relevant agency, law enforcement, data protection authorities, and financial regulators.
- Fraudulent requests from a real government domain were handled as legal compliance
- Revolut has over 80 million customers; 'very limited' number affected
- Disclosed: IDs, verification selfies, account statements, transaction histories
- No system intrusion and funds unaffected; regulators and law enforcement notified
- Likely consumer impact is second-stage fraud and identity theft attempts
Full article513 words · extracted from malwarebytes.com · click to collapse
Revolut has acknowledged that it disclosed sensitive customer records to an unauthorized party. The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain, according to TechCrunch.
Revolut is a London-based banking and financial platform with more than 80 million customers globally, according to the company.
Revolut describes this as an external impersonation scam, not an intrusion into its systems. It also says customer funds were not affected. Revolut has not identified the government agency or disclosed its email domain.
The attacker appears to have abused the trust attached to a real government email domain to make bogus requests for customer information. Revolut detected the activity, blocked the sending address, and says it notified the relevant agency, law enforcement, data protection authorities, and financial regulators.
“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators.”
Through this social engineering attack, rather than by gaining access to Revolut’s systems, the criminals obtained the following types of information about customers:
- Identity and contact information like dates of birth, postal address, email address, and phone number.
- Copies of IDs such as passports and driver’s licenses.
- Verification selfies.
- Account statements and transaction histories.
Revolut has said only that a “limited” or “very limited” number of customers were affected, and that it contacted them directly.
Those customers have received or will receive an email specifying which of their personal data was disclosed:

How to stay safe
The likely consumer impact will be second-stage fraud attempts rather than immediate unauthorized transfers. Here are some guidelines to help keep your money safe:
Treat any unexpected Revolut-related contact as suspicious, especially calls, emails, WhatsApp messages, or text messages claiming you need to “secure” an account, reverse a transfer, or replace documents. Do not use links or phone numbers supplied in the message. Revolut advises ending contact with suspected scammers and contacting the company through official channels.
IDs and other exposed information could be used for identity theft. Monitor your accounts and credit reports for unfamiliar account openings or credit applications, and consider placing a fraud alert or using credit monitoring where available in your country.
If you received a notification email, check your balances, cards, beneficiaries, recent transfers, account statements, and linked devices. Report any unfamiliar activity immediately through Revolut’s secure in-app chat.
If you were involved in a data breach, read our blog Involved in a data breach? Here’s what you need to know for more recommendations.
Pro tip: Use Malwarebytes Scam Guard to analyze any suspicious communications. It can help you determine whether a message is a scam and advise you on what to do next.
Let’s face it, an incognito window can only do so much. Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance.
About the author
Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.malwarebytes.com/blog/news/2026/09/revolut-gave-customer-ids-and-financial-data-to-a-government-impostor