Revolut said on Sept. 16 that it had received no direct contact or demand from the people claiming responsibility for a customer-data breach, a new statement that leaves the identity and intent of the actors unresolved while increasing scrutiny of the fintech’s process for authenticating government requests.

The company had already confirmed that it disclosed sensitive information to an unauthorized third party after fraudulent requests arrived through a legitimate government-agency email domain. Revolut characterized the event as an external impersonation scam and said its core systems and customer funds were not affected.

What Revolut has confirmed

TechCrunch reported that a notice sent to affected customers listed potentially exposed identity and contact information, including dates of birth, addresses, phone numbers and copies of passports or driver’s licenses. Verification selfies, account statements, IBANs and transaction histories may also have been disclosed.

Revolut said a limited number of customers were affected but has not publicly identified the government agency involved, the markets covered or the exact number of people whose records were disclosed. The company said it blocked the email address, contacted affected customers and notified the relevant agency, law enforcement and regulators.

In its Sept. 16 response, reported by Reuters through Euronext, Revolut said it had not communicated directly with the people or group claiming responsibility and had not received a direct demand from them. That statement does not resolve how the fraudulent requests were authorized or whether exposed data has circulated further.

The control failure extends beyond email security

The commercial risk is not limited to a compromised inbox. Banks and financial platforms routinely answer lawful requests from regulators and law-enforcement agencies, but a message sent from an authentic domain can still be fraudulent. Domain authentication establishes where a message originated; it does not establish that the sender is authorized to seek a particular customer’s records.

For financial-services leaders, the incident raises practical questions about out-of-band confirmation, request-specific legal review, data minimization and escalation procedures for unusually broad demands. Sensitive identity documents and transaction histories warrant controls that verify both the requesting institution and the named official before records leave the company.

Infosecurity Magazine separately reported that Revolut described the affected population as a very limited group and said its systems and funds remained untouched. Customers who received a notification should follow Revolut’s instructions, watch for targeted phishing attempts and treat unexpected account or identity-verification messages cautiously.