British fintech company Revolut has confirmed that it disclosed sensitive customer information to an unauthorised third party. The disclosure occurred after the company received fraudulent requests sent from an email domain belonging to a legitimate government agency.
The exposed data included customers’ identity and contact details, such as birth dates, postal and email addresses, and phone numbers. Copies of identity documents, including passports and driver’s licences, were also exposed. Revolut’s notification to affected customers stated that the data may also have included verification selfies, account statements, and transaction histories.
A Revolut spokesperson confirmed that a “limited” number of customers were impacted and that the company had contacted those customers directly. The firm did not disclose the exact number of individuals affected, nor did it specify if the incident was limited to a particular market or identify the government agency involved.
Revolut stated that it blocked the email address upon discovering the scam and alerted the relevant government agency, law enforcement, and regulators. The company added that its “systems and customer funds are unaffected.”