British neobank Revolut exposed sensitive customer information after falling for fraudulent requests sent from a legitimate government agency email domain. Blockchain investigator ZachXBT shared customer notifications showing KYC data exposure including identity documents, verification selfies, account statements, IBANs, and full transaction histories.
Revolut confirmed the attack but did not specify victim count or the government agency involved. The company blocked the email address and alerted government officials, law enforcement, and regulators. Systems and customer funds were unaffected.
The incident highlights compliance workflow vulnerabilities when verifying government data requests in fintech.