Revolut, which earlier this month received conditional approval from the Office of the Comptroller of the Currency to form a national bank, confirmed over the weekend that it suffered a data breach after falling victim to fraudsters identifying themselves as a government agency.
The company said that its systems and customer funds were unaffected, and only a limited group of users were compromised in the incident, which it called a “sophisticated external impersonation scam” where a legitimate government domain email address was used to steal information.
The incident highlights the increasingly sophisticated tactics employed by fraudsters, which are likely to become even more effective as bad actors incorporate AI into their toolboxes.
Ken Palla, an online security expert who spent more than two decades at the former Union Bank, told This Week in Fintech that this was the first time he had heard of a financial institution falling for this type of scam, and warned that other companies are susceptible and could face similar attacks.
“I think the fintechs have to really think about security in a very serious way,” Palla said. “It’s all about growing customers and growing revenue. But in today’s world, the fraudsters just love you because you’re not paying attention to security.”
Photo by Julio Lopez on Unsplash
Revolut is Europe’s most valuable fintech firm. The company says it has over 80 million customers and processed £986 billion of retail transaction volume in 2025, with before tax profit of £1.7 billion on revenue of £4.5 billion in the period.
Contact Info, Verification Details
Among the data that was exposed were customer identities, contact details, postal and email addresses and phone numbers, according to TechCrunch, which cited a notification email sent to affected customers. Also among the exposed information were passports, driver’s licenses and other verification documents, media reports noted.
Revolut did not provide the exact number of customers affected or identify the specific department hit, citing an ongoing investigation, but the Financial Times reported that roughly 700 users had their information compromised.
“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators,” the company said in a statement.
“We have contacted the limited number of impacted individuals directly to inform them and provide support."
Palla said that from the customers to large companies, security can be — and needs to be — beefed up by verifying sources through multiple pathways.
Photo by Markus Winkler on Unsplash
“It’s not just consumers that are being scammed, but it’s also businesses,” Palla said. “If you’re a bank and you’re getting a call, an email from the government saying ‘I need this information,’ you probably need to double-check it [and] do an out-of-channel verification.”
He pointed to countries like Singapore as having better regulatory action when it comes to online fraud, and suggested that the United States needs to catch up. The rise of AI as a tool used by fraudsters will increase that urgency, Palla said.
“The banks have to put more controls in because their payment rails are being used,” he said. “Everybody has to get into the fight…we have to get into what I call a wartime footing to fight this.”

