London — British fintech Revolut has notified around 680 customers that their sensitive personal, identity and financial data was disclosed to unauthorized third parties after the company fulfilled fraudulent information requests sent from a legitimate government agency email domain. Britain’s Information Commissioner’s Office (ICO) has opened an investigation into the incident.
The company described the episode as a “sophisticated external impersonation scam.” Attackers used an email account operating on a genuine government domain that passed standard authentication checks. Revolut treated the requests as legitimate legal or compliance inquiries and provided the data before discovering the deception.
What was exposed
According to customer notifications and reports citing those notices, the disclosed information for the affected individuals included:
- Full names, dates of birth, postal and email addresses, phone numbers and occupations
- Copies of identity documents such as passports and driver’s licenses
- Verification selfies
- Account statements, IBANs, withdrawal records and full transaction histories, including Bitcoin activity
Revolut has stressed that its core systems, databases and customer funds were not compromised. The company said it immediately blocked the email address once the scam was identified, alerted the relevant government agency, law enforcement, data-protection authorities and financial regulators, and contacted the impacted customers directly.
Revolut has publicly referred only to a “very limited” or “limited” number of customers. Multiple reports, including those citing sources close to the matter and the Financial Times, put the figure contacted after the initial investigation at 680. The firm has not independently confirmed the exact number or named the specific government agency domain involved.
Notable victims and threats
Former Mt. Gox chief executive Mark Karpelès was among those notified. He publicly shared details of the notice he received, which listed potential exposure of statements, IBANs, withdrawal records and Bitcoin-related transaction history.
Individuals claiming responsibility for the data have threatened further releases and sought payment from Revolut. The company has not confirmed any ransom demands or negotiations.
Regulatory response
The ICO confirmed it is investigating after Revolut reported the incident. An investigation does not automatically mean a finding of a data-protection breach under UK law; the regulator will examine the circumstances of the disclosure and Revolut’s handling of the matter. The Financial Conduct Authority has also said it is engaging with the firm to understand the impact and steps being taken.
Context and implications
Revolut, one of Europe’s largest fintechs and a newly authorized UK bank, has grown rapidly with tens of millions of customers. The incident highlights risks around social-engineering and business-email-compromise style attacks that abuse trusted domains rather than traditional network intrusions. High-net-worth and crypto-active users appear to have been among those targeted, according to on-chain investigators and public statements from affected individuals.
Revolut has said customer funds remain safe and that it is supporting those affected. Customers who have not received a direct notification are not believed to be part of the limited group identified so far. Anyone concerned about their account is advised to monitor statements, enable strong authentication, and contact Revolut support through official channels only.
The probe by the ICO is ongoing. Revolut continues to cooperate with authorities.
