discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Revolut discloses data breach exposing financial info, passports

Fintech company Revolut has disclosed a data breach after a threat actor, impersonating a government agency via email, obtained sensitive customer data, including identity documents and financial information.

By Sergiu Gatlan·Sep 14·bleepingcomputer.com·3 min read

Intelligence analysis by Gemini 2.5 Flash

Revolut discloses data breach exposing financial info, passports
Image: bleepingcomputer.com

Revolut, a global fintech firm serving over 80 million customers, fell victim to a sophisticated social engineering attack. An unauthorized email, appearing to originate from an official government agency's domain, tricked the company into releasing personally identifiable information (PII), financial records, and copies of identity documents like passports and driver's licenses for a…

Why it matters

This story matters to the Security community as it highlights the persistent effectiveness of social engineering tactics, specifically email impersonation, even against large financial institutions. The breach underscores the critical need for advanced verification protocols to prevent the exposure of highly sensitive customer data, including identity documents and full transaction hi…

Imagine a sneaky trickster pretending to be a grown-up from the government, sending an email to a big money company called Revolut. Because the email looked super real, Revolut accidentally gave the trickster some secret papers about a few of its customers, like their names, birthdays, where they live, and even copies of their passports and how much money they have. It's like someone pretending to be your teacher and getting your report card from the school office.

Analysis

The recent data breach at Revolut underscores the evolving sophistication of cyber threats, particularly those leveraging social engineering. The incident involved a threat actor successfully impersonating a government agency through an email sent from what appeared to be an official domain. Revolut stated that the communication carried "valid domain authentication credentials," leading them to believe it was an authentic request. This method bypasses many traditional technical defenses, relying instead on human trust and the perceived legitimacy of the sender, making it a challenging vector to defend against.

Government Impersonation

The core of the Revolut breach lies in the attacker's ability to convincingly impersonate a government agency. By using an "unauthorised email account sent directly using the official government agency's email domain," the threat actor exploited a critical vulnerability in Revolut's verification process. The company's statement that the communication carried "valid domain authentication credentials" suggests that the email passed initial legitimacy checks, likely due to compromised credentials or a sophisticated spoofing technique that mimicked the agency's domain. This incident serves as a stark reminder that even with technical safeguards, the human element remains a significant target for attackers, especially when requests appear to come from authoritative sources.

Customer Data

The scope of the exposed customer data is particularly concerning, encompassing a wide array of highly sensitive information. This includes identity details such as full name, date of birth, and occupation, alongside contact details like postal address, email, and telephone number. More critically, the breach exposed document and verification data, specifically copies of identity documents like passports and driver's licenses, as well as facial verification images used for Know Your Client (KYC) processes. Furthermore, account statements, IBAN numbers, withdrawal records, and full transaction histories, including Bitcoin transactions, were compromised. Such a comprehensive data set significantly increases the risk of identity theft, targeted phishing, and financial fraud for the affected individuals.

Revolut's Response

Upon detecting the breach, Revolut claims to have acted swiftly, immediately blocking the malicious address and alerting relevant government agencies, enforcement bodies, data protection authorities, and financial regulators. The company emphasized that its "systems and customer funds are unaffected," aiming to reassure its vast customer base. While Revolut has refused to disclose the exact number of affected customers, stating it was a "very limited" group, crypto fraud investigator ZachXBT suggested the breach might have targeted "high net worth users." This incident is not Revolut's first encounter with a data breach; four years prior, in September 2022, the company disclosed another breach affecting 50,150 customers, where personal, contact, and financial information was stolen. This pattern raises questions about the robustness of Revolut's ongoing security measures and its ability to prevent sophisticated social engineering attacks.

Key points

  • Revolut disclosed a data breach caused by a threat actor impersonating a government agency via email.
  • The attacker used an unauthorized email account from an official government agency's domain, tricking Revolut into fulfilling the request.
  • Exposed data includes full names, dates of birth, occupations, contact details, copies of passports/driver's licenses, facial verification images, account statements, IBANs, withdrawal records, and full transaction history (including Bitcoin).
  • Revolut states its systems and customer funds are unaffected and that a "very limited" number of customers were impacted.
  • This is Revolut's second data breach in four years, following a similar incident in September 2022 that affected 50,150 customers.
The Upside

Revolut's swift action in blocking the malicious address and alerting relevant authorities demonstrates a rapid response to contain the incident. The company's assertion that its systems and customer funds remain unaffected, coupled with the "very limited" number of affected customers, suggests the breach's overall impact might be contained.

The Downside

The exposure of highly sensitive data, including passports and full financial histories, poses a severe risk of identity theft and targeted fraud for the affected individuals, especially if they are high-net-worth users. This incident marks Revolut's second data breach in four years, which could erode customer trust and raise concerns about the company's long-term security resilience against sophisticated social engineering attacks.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritydata-breachfintechsocial-engineeringidentity-theftbanking

Author

Sergiu Gatlan

Intelligence analysis by

Gemini 2.5 Flash

Published

Sep 14, 2026

Source

bleepingcomputer.com

Share

Topics

securitydata-breachfintechsocial-engineeringidentity-theftbanking

Related

More from this desk

Oct 7·thehackernews.com

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, including a serious SSRF bug rated 10.0 on the CVSS scale.

Oct 7·bleepingcomputer.com

Microsoft Outlook to block MSIX attachments starting November

Microsoft Outlook to block MSIX attachments starting November 2026.

Oct 7·bleepingcomputer.com

PoeLLM malware infects exposed AI servers in cryptomining attacks

PoeLLM malware targets exposed AI servers, using a poem for C2 addresses. Researchers found 3,400 compromised servers, with activity peaking at 800 infected systems.

Oct 7·bleepingcomputer.com

Ransomware has a new target. Is your backup ready?

Ransomware groups are targeting backups, making them a new threat. IT leaders need to secure their backups to prevent data loss.