Revolut Data Breach: Financial and Passport Data Compromised via Social Engineering
Revolut has confirmed a data breach where a threat actor, impersonating a government agency, obtained sensitive customer data including financial information and passports.
Assessment
Revolut has confirmed a data breach where a threat actor, impersonating a government agency, obtained sensitive customer data including financial information and passports. The incident, attributed to social engineering via fraudulent government email requests, has affected an undisclosed number of users in GB and a small number of Irish customers. The full scope of affected clients and specific data types remains unclear.
Why it matters: This breach raises significant concerns regarding identity theft, financial fraud, and regulatory scrutiny for Revolut and the broader fintech sector.
Established
- ·Confirmed: Revolut experienced a data breach.
- ·Confirmed: Threat actor impersonated a government agency.
- ·Confirmed: Customer data, including financial information and passports, was obtained.
- ·Confirmed: Breach occurred via fraudulent requests from a legitimate government agency's email domain.
- ·Confirmed: A small number of Irish customers were affected.
- ·Unclear: The total number of affected users.
- ·Unclear: The full scope of specific data types compromised.
Indicators to watch
- →Official statements from Revolut detailing the number of affected users and specific data types.
- →Regulatory investigations and potential fines.
- →Reports of identity theft or financial fraud linked to affected Revolut customers.
Evidence
Central claim Revolut discloses data breach exposing financial info, passports100% on claim
Topics data breach · fintech · identity theft · social engineering · revolut · data-breach · scam · customer-data · cybersecurity · phishing
Discussion
…Sign in to add a note, contribute a source, or challenge the assessment.