Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests from a legitimate government agency email domain. The company said a limited number of customers were affected, contacted them directly and maintained that its systems and customer funds were unaffected. Confirmed exposed information included birth dates, postal and email addresses, phone numbers and passport or driver's-license copies. Verification selfies, account statements and transaction histories were identified as possible exposures rather than confirmed for every affected customer. Decrypt reported that the notice also referenced Bitcoin transaction histories, wallet reference numbers, IBANs and withdrawal records, though those details have not been independently confirmed. Revolut said it blocked the email address and alerted the relevant agency, law enforcement and regulators, while declining to identify the agency, disclose an affected-customer figure or specify the incident's timing and geographic scope.