Revolut leaked customer KYC data after falling for government impersonation scam
The fintech giant voluntarily handed over passports and transaction histories to scammers posing as government officials.
Fintech giant Revolut has disclosed a significant data breach after employees fell victim to a sophisticated impersonation scam. The company inadvertently leaked sensitive customer information to an unauthorized third party by fulfilling fraudulent requests that appeared to come from a government agency.
According to a Revolut spokesperson, the attackers utilized a legitimate government agency email domain to submit requests for information. Believing these inquiries were official, Revolut voluntarily provided the data. The breach was not the result of a technical system hack or a software vulnerability, but rather a failure in human verification processes. The exposed data is extensive, including birth dates, postal and email addresses, and phone numbers. More critically, the leak included high-value KYC (Know Your Customer) documents such as copies of passports, driver's licenses, and verification selfies, alongside account statements and transaction histories.
The Scale of the Risk
Revolut currently serves over 80 million customers globally and is in a period of aggressive growth. The company is expanding its banking footprint across Europe and India, and has received conditional approval for a national bank in the U.S., with full operations expected by 2027. Furthermore, the firm is reportedly eyeing a public listing that could see its valuation reach as high as $200 billion.
Why It Matters
This incident is particularly damaging because it exposes the fragility of manual verification workflows within a company positioning itself as a secure, tech-forward financial institution. The loss of government-issued IDs and biometric selfies creates a severe, long-term risk of identity theft for the affected users, as these documents are often used as primary anchors for identity verification across the financial sector. While technical hacks are common, the voluntary surrender of data to a fraudulent actor highlights a critical gap in the company's internal security protocols.
Next Steps
Revolut has since blocked the fraudulent email address and has notified the affected customers, relevant regulators, and law enforcement agencies. While the company has confirmed the mechanism of the breach, the full number of impacted users has not been disclosed. Industry observers will be watching to see if this lapse prompts a wider audit of how the fintech handles government data requests as it moves toward a potential IPO.