Fintech company Revolut recently confirmed that it fell victim to a sophisticated impersonation scam, leading to the disclosure of sensitive customer information to an unauthorized third party. The scam involved fraudulent requests sent from an email domain belonging to a legitimate government agency, which allowed them to bypass Revolut's authentication checks.

The exposed data included a range of personal and financial details. This encompassed customers' identity and contact information, such as birth dates, postal and email addresses, and phone numbers. Crucially, copies of identity documents like passports and driver's licenses, along with verification selfies, account statements, and transaction histories (including Bitcoin transactions), were also compromised. According to sources, the incident was believed to be targeted at high-net-worth individuals.

Revolut stated that a "limited number" of its more than 80 million global customers were impacted and that those affected have been directly contacted. The company did not specify the exact number of individuals affected or the government agency involved but confirmed it immediately blocked the fraudulent email address and alerted relevant government agencies, law enforcement, data protection authorities, and financial regulators. Revolut also emphasized that its systems and customer funds remain unaffected. The incident comes as Revolut weighs a potential public listing with a valuation as high as $200 billion.