Revolut says customer identity documents were exposed in a scam
An unauthorised third party used a legitimate government email domain. The exposed data included passports, driving licences and verification selfies; the company says only a limited number of customers were affected.

The British fintech firm Revolut confirmed on Saturday that sensitive customer data was exposed in a scam involving an unauthorised third party who used a legitimate government email domain.
The company said only a limited number of customers were affected, and that it has contacted them directly.
What was exposed
According to a TechCrunch report, the disclosed information included customers' identity and contact details — dates of birth, postal and email addresses, and phone numbers — along with copies of identity documents such as passports and driving licences.
The exposed data may also have included verification selfies, account statements and transaction histories.
That combination is the significant part: identity documents and a verification selfie are harder for a customer to change than a password or a card number.
The method
The scam involved an unauthorised third party using a legitimate government email domain.
Revolut describes the domain used as legitimate, which is what distinguishes this from a spoofed address. It obtained data through a request that appeared authorised rather than through a technical breach.
Revolut said it blocked the email address after discovering the scam, and notified the relevant government agency, law enforcement and regulators.
What the company says was not affected
"Revolut systems and customer funds are unaffected," the company said.
That distinction is real but partial: a data disclosure obtained through a fraudulent request is not a compromise of the platform, and it does not touch balances. It does put documents in circulation.
Who was targeted
Crypto security researcher ZachXBT shared details of Revolut's email to affected customers late on Friday. According to the researcher, the incident appeared to have targeted high-net-worth users.
If that holds, it points to a selective request rather than a bulk extraction — someone asking for specific customers' records.
What has not been disclosed
Revolut has not said how many people were affected, beyond describing the number as limited.
It has also not said whether the incident was confined to a particular market, or which government agency's email domain was involved.
Those two omissions matter for customers trying to work out whether they are exposed. Without a market or a number, the only people who know are those the company has contacted.
What affected customers face
Revolut says it has contacted affected customers directly. It has not said what it is advising them to do, and TechCrunch's account does not record any guidance issued alongside the notification.



