Revolut confirmed that customer personal data leaked through a social engineering attack using a spoofed government email address. The breach exposed sensitive information including passport scans, selfies, and complete financial transaction histories for an undisclosed number of users.

The attack exploited Revolut's internal processes by impersonating a government agency. An attacker sent a fake official request to Revolut staff, tricking employees into releasing customer data without proper verification. The fraudster obtained comprehensive KYC (know-your-identity) documents alongside transaction records, creating a severe privacy and identity theft risk for affected customers.

Revolut operates as a fintech platform offering banking services and crypto exchange capabilities. The company maintains regulatory licenses across multiple jurisdictions and handles millions of customer accounts globally. Its platform integrates traditional banking features with cryptocurrency trading, making it a high-value target for social engineers seeking access to both banking and crypto-related personal data.

This incident underscores a persistent vulnerability in regulated fintech companies. Even platforms with strict compliance requirements remain susceptible to internal fraud when attackers bypass technical security through social engineering. Government impersonation carries psychological weight that pressures support staff to act quickly without standard verification protocols. Passports and government ID photos represent some of the most valuable data on darknet markets, commanding premium prices from identity theft rings. Combined with transaction histories, fraudsters gain complete financial profiles enabling account takeovers, loan applications, and crypto wallet compromise.

Revolut did not specify the attack date, number of affected users, or which government agency domain was spoofed. The company stated it notified impacted customers and law enforcement. The lack of transparency raises questions about breach scope and timeline. Industry practice typically requires disclosure within 72 hours in most European jurisdictions where Revolut operates, but the company's announcement provides minimal detail about compliance with these requirements.

This represents the latest in a series of fintech breaches targeting customer identity documents and financial data. Similar attacks have struck other crypto-friendly platforms and traditional banking apps. The fintech sector remains under-resourced on internal security training compared to legacy banks, creating organizational vulnerability despite robust technical infrastructure.

For Revolut customers, the exposure carries dual risk. Compromised passport data and selfies enable sophisticated identity fraud including SIM swaps and account recovery attacks. Transaction histories reveal spending patterns, asset holdings, and cryptocurrency purchase behavior. Combined datasets allow attackers to target high-net-worth users for follow-up phishing or direct fraud schemes.

Regulatory bodies will scrutinize Revolut's incident response and internal controls. Financial regulators expect companies to implement multi-factor verification for sensitive data requests, employee security training, and proper audit logging of all customer record access. The breach may trigger compliance reviews across UK, EU, and other jurisdictions where Revolut operates, potentially resulting in fines or operational restrictions.

The incident demonstrates that fintech companies cannot rely on technical security alone. Human verification remains the weakest link in security chains. Organizations handling sensitive financial and identity data require robust internal processes, regular security awareness training, and strict verification protocols for all data requests regardless of apparent legitimacy or urgency.