Revolut, the London-headquartered digital bank, has confirmed that a sophisticated impersonation attack led to the exposure of personal data belonging to roughly 680 customers across several European countries, including the United Kingdom. The breach, which the company described as an “external impersonation scam,” involved an unauthorised third party using an email address from a legitimate government agency domain to submit fraudulent requests for customer information.
According to the Financial Times, the attackers were Italian hackers who gained access to a compromised Italian government email account. They then posed as officials to request sensitive customer details from Revolut. The data obtained included customers’ home addresses, verification photographs, identity documents, and information related to bitcoin activity.
Revolut, which operates its European banking business under a Lithuanian licence, said it detected the attack promptly and took immediate action. “Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection and financial regulators,” the company said in a statement. It also emphasised that its systems and customer funds were “unaffected” and that it had contacted all affected individuals to inform them and offer support.
The UK’s Information Commissioner’s Office (ICO) confirmed it had received a report about the incident and is currently assessing the information provided. The breach comes at a time when Revolut is aggressively expanding its banking footprint across Europe and beyond.
Revolut’s rapid expansion
Founded in 2015 as a fintech start-up specialising in smartphone-based currency exchange and money transfers, Revolut has grown into one of Europe’s most valuable financial technology companies. In July, a secondary share sale valued the company at $115 billion (€98.7 billion).
The company has been steadily securing banking licences to compete with traditional retail banks. In March, it obtained a long-awaited UK banking licence, lifting restrictions on its ability to offer a fuller range of banking services in its home market. In August, it received a full French banking licence, and this month it secured conditional approval for a US banking licence. On Tuesday, Revolut also filed an application for a banking licence in Switzerland.
Revolut now serves more than 80 million customers globally and is targeting 100 million customers across 100 countries. Its European operations are legally based in Lithuania, where it holds a European banking licence, allowing it to passport services across the EU.
This incident highlights the growing threat of phishing and impersonation attacks targeting financial institutions and their customers. While Revolut has not disclosed the exact number of UK customers affected, the source familiar with the matter said the total across Europe was around 680.
Cybersecurity experts note that such attacks are becoming increasingly sophisticated, often exploiting trust in government communications. “This is a classic example of social engineering,” said one analyst. “The attackers didn’t break into Revolut’s systems; they tricked the company into handing over data by impersonating a trusted authority.”
Revolut has advised affected customers to be vigilant for any suspicious activity and to contact its support team if they have concerns. The company is also cooperating with law enforcement and regulatory bodies across the affected jurisdictions.
As Revolut continues its rapid expansion, this breach serves as a reminder that even the most innovative fintechs are not immune to the persistent threat of cybercrime. The company’s response will be closely watched by regulators and customers alike, as trust is paramount in the digital banking sector.


