
Revolut has confirmed a customer data breach that should worry every fintech, bank and crypto platform that relies on official-looking requests as part of its compliance process.
The British fintech said sensitive customer information was disclosed to an unauthorised third party after fraudulent requests were sent from a legitimate government agency email domain. A company spokesperson told Reuters via Channel NewsAsia that Revolut blocked the email address after discovering the impersonation scam and alerted the relevant government agency, law enforcement, data protection authorities and financial regulators.
Revolut says its systems and customer funds were not affected. That is an important reassurance, but it does not make the breach minor. Customer notices reviewed by The Block say exposed information may have included names, dates of birth, postal and email addresses, phone numbers, identity documents, verification selfies, account statements, IBANs, withdrawal records and transaction histories, including Bitcoin activity.
The most troubling part of this case is that the request reportedly came through a real government domain. That is exactly the kind of signal compliance and fraud teams are trained to take seriously. If attackers can compromise or misuse official channels, they do not always need to break into a fintech’s core systems. They can pressure the company into handing over data through a process that looks legitimate.
For users, the danger is not limited to embarrassment or privacy loss. Identity documents, transaction histories and crypto records can be used for targeted phishing, account takeover attempts, blackmail, social engineering or surveillance. Even if the number of affected customers is limited, the quality of the data matters.
This is also a useful warning for African fintechs and digital banks. Regulators often expect fast cooperation from financial institutions, especially when fraud, money laundering or law enforcement requests are involved. But speed cannot replace verification. TechBooky recently wrote about how cyber risk can shake public trust in banks and fintechs, and the Revolut case shows that compliance workflows themselves can become attack surfaces.
The right lesson is not that companies should ignore official requests. It is that official requests need stronger authentication, secondary confirmation, audit trails and human checks when the requested information is sensitive. Fintech security is no longer just about protecting apps and servers. It is also about protecting the channels through which powerful institutions ask for customer data.






