Revolut says customer data exposed through fake government email

Summary

Revolut disclosed a data breach in which sensitive customer information was exposed after scammers used a legitimate government agency email domain to submit fraudulent information requests. The compromised data included passport copies, verification selfies, and full transaction histories. Revolut initially passed authentication checks on the requests, later determined they were fake, blocked the sender, and notified the relevant agency, law enforcement, and financial regulators. The company said its systems and customer funds were not affected and that only a limited number of customers were impacted, who were contacted directly. The incident sparked criticism online about mandatory identity verification and KYC requirements.