Revolut disclosed sensitive customer information to an unauthorized third party that submitted fraudulent requests for records from a legitimate government agency email domain, the company told TechCrunch on Saturday.
A Revolut spokesperson described the incident to The Block as a "sophisticated external impersonation scam" and said the company blocked the email address after identifying it. The spokesperson said Revolut's systems and customer funds were unaffected.
Revolut said a limited number of customers were affected and that it has contacted them directly, with some of the customers reporting receiving emails on Friday. The company declined to disclose to The Block how many people were affected, whether the incident was confined to a single market, and which government agency domain was used.
The information disclosed may have included customers' names, dates of birth, postal and email addresses, telephone numbers and copies of identity documents including passports and driver's licenses, according to a notification sent to affected customers. Verification selfies, account statements and transaction histories may also have been disclosed.
A copy of Revolut's notice to customers shared publicly by former Mt. Gox CEO Mark Karpelès, who said he was among those affected, said account statements, IBANs, withdrawal records and full transaction histories, including Bitcoin transactions, were among the details that were potentially shared with the unauthorized third party.










