Revolut says a limited number of customers have had sensitive information exposed after a scam carried out by an unauthorized third party. The company reports that the incident involves an email-based attempt that used a legitimate government email domain to appear credible, according to Bloomberg and PYMNTS.

Revolut states it has identified the issue and taken steps to block the relevant address, and it is communicating with affected customers. The outlets report that the exposure is limited to some users rather than the wider customer base, but do not detail the specific type of data disclosed or the full scope of the attack. Both sources frame the event as a phishing or social-engineering campaign rather than a confirmed data breach of Revolut systems.

The reporting largely differs in emphasis: PYMNTS focuses on Revolut’s disclosure and the scam mechanism, while Bloomberg emphasizes the company’s statement about the “limited number” of impacted customers and the use of a legitimate government domain to carry out the fraud.