Fintech giant Revolut has confirmed a data breach that exposed sensitive information belonging to a limited number of customers. According to the company, scammers used a legitimate government email domain to send fraudulent requests, which led to some customer data being handed over.

What happened?

Attackers exploited an authentic government domain, making their requests look official. Revolut admitted the breach and stressed that only a small group of users was affected. The company hasn't shared any numbers or further specifics about how many people were involved.

What kind of data was leaked?

On-chain investigator ZachXBT flagged the incident, noting that the compromised data could include document copies, bank statements, and full transaction histories—including Bitcoin (BTC) transfers. That suggests some users’ personal and financial info might be out in the wild.

Why does this matter for customers?

Leaks like this ramp up the risk of targeted attacks and threaten users’ financial privacy—especially if entire crypto transaction histories are exposed. If you think you might be affected, it’s smart to keep a close eye on your account activity and any unusual notifications from your services.