Revolut confirms data breach after fraudsters spoofed a government agency's email
Fintech firm Revolut has confirmed that fraudsters, abusing a legitimate government agency's email domain, tricked it into handing over customer personal data and ID documents; a hacker group now threatens to leak the data unless paid.

What happened
London-based fintech Revolut has admitted disclosing sensitive customer records to an unauthorized party after accepting fraudulent information requests sent from a genuine government agency email domain, according to TechCrunch and Malwarebytes. Revolut describes the incident as an external impersonation scam rather than an intrusion into its own systems, and says customer funds, accounts, and core infrastructure were not affected.
What data was exposed
The disclosed information includes customers' identity and contact details — date of birth, postal and email address, and phone number — as well as copies of identity documents such as passports and driver's licenses, facial verification selfies, account statements, and transaction histories, according to a notification email sent to affected customers and reviewed by TechCrunch. Revolut says only a "limited" or "very limited" number of customers were affected but has not disclosed an exact figure. Crypto security researcher ZachXBT said the attack appeared to target high-net-worth users.
Extortion threat
City AM reports an element not mentioned by the other sources: a hacker group calling itself "Revolut Smilik" told the outlet it is demanding payment from Revolut and threatened to release "more and more data everyday" if the ransom is not paid. According to City AM, data on several notable individuals has already been leaked, though the company and the hackers have not yet had direct contact.
Response and oversight
Revolut says it blocked the fraudulent email address immediately upon detection and alerted the relevant government agency, law enforcement, data protection authorities, and financial regulators, but it has not named the agency or the country involved. The UK's Financial Conduct Authority (FCA) and the Information Commissioner's Office (ICO) both confirmed they are aware of the incident and are assessing it.
Context
Revolut operates in more than 30 countries and serves over 80 million customers globally. The incident comes as the company, according to TechCrunch, is reportedly weighing a public listing that could value it at up to $200 billion, up from a $75 billion private valuation in November; City AM, however, notes that a secondary share sale launched earlier this year values the firm at around $115 billion. Malwarebytes advises affected customers to treat unexpected Revolut-related calls or messages with suspicion and to monitor their accounts and credit history.


