Financial technology company Revolut confirmed the exposure of sensitive customer data following a sophisticated impersonation scam. The breach occurred when an unauthorized third party used a legitimate government agency email domain to submit fraudulent information requests that passed internal authentication checks. Compromised data included copies of passports, verification selfies, and full transaction histories for a limited number of high-net-worth users.

Upon detection, Revolut blocked the malicious address and notified the relevant government agency, enforcement bodies, and financial regulators. A company spokesperson stated that core systems and customer funds remained unaffected, with direct contact made to impacted individuals for support. Crypto analyst ZachXBT characterized the incident as targeted rather than widespread, while some users on social media criticized mandatory KYC protocols for increasing risk without providing meaningful security benefits.