Photo: depositphotos
British fintech company Revolut has confirmed that sensitive personal data belonging to a limited number of customers was compromised after attackers used an impersonation scheme to submit fraudulent information requests from an email address using the domain of a legitimate government agency, Reuters reports.
Revolut said a “very limited” number of customers were affected and that the company had contacted them directly. It did not disclose the exact number.
The compromised information included full names, dates of birth, postal and email addresses, phone numbers, and copies of passports and driving licences.
According to TechCrunch, which reviewed a notification sent to affected customers, the attackers may also have accessed verification selfies, bank statements and transaction histories, including Bitcoin transactions.
Revolut said it immediately blocked the suspicious email address after detecting the fraud and notified the relevant government authority, law-enforcement agencies, data-protection authorities and financial regulators.
Cybersecurity researcher ZachXBT, who specializes in cryptocurrency investigations, said the attack appeared to have been targeted, particularly at wealthy Revolut customers and people holding cryptocurrency assets.
Breach comes amid IPO preparations
The data breach comes as Revolut is preparing for a possible initial public offering (IPO) that could value the company at up to $200 billion.
The fintech was privately valued at $75 billion in November.
Revolut has more than 80 million customers and operates as a bank in more than 30 countries. The company has also received approvals to expand its operations in the European Union, the United Kingdom and the United States.
Revolut and Ukrainian customers
Revolut entered the Ukrainian market in February 2025 but suspended new customer registrations several months later because it did not hold a Ukrainian banking license.
Ukraine’s National Bank said Revolut’s Lithuanian banking license did not authorize it to provide services to Ukrainian residents and that its customers were not covered by Ukraine’s deposit-guarantee system.
In December 2025, Revolut began closing accounts held by Ukrainian residents, with an exception for Ukrainians officially living and registered in countries of the European Economic Area. Their accounts remained active.
The distinction remains relevant following the latest breach, as many Ukrainians living abroad continue to use Revolut.