Revolut has confirmed that an unauthorised third party obtained sensitive customer records after sending fraudulent requests from a legitimate government agency email domain.
The data covered dates of birth, postal and email addresses, phone numbers and copies of identity documents including passports and driving licences, according to a notification sent to affected customers and reviewed by TechCrunch. Verification selfies, account statements and transaction records may also have been exposed.
A spokesperson called the affected group limited and said those customers were contacted directly, without giving a number or naming the agency involved.
Revolut said it blocked the address after discovering the impersonation and alerted the agency, law enforcement and regulators, adding that its systems and customer funds were unaffected.
Crypto researcher ZachXBT, who surfaced the customer email, said the campaign appeared aimed at high net worth users.
The incident lands at an awkward moment for a company weighing a public listing that could value it near $200B, up from a $75B private mark in November. Revolut serves more than 80 million customers and operates as a bank in over 30 countries, and this month won conditional approval from the US Office of the Comptroller of the Currency for a national charter.
Impersonation through trusted domains is a growing problem for fintechs, which hold exactly the identity documents attackers find most useful.