Personal, Financial Info Exposed in Revolut Data Breach
Revolut, a British fintech company, experienced a data breach where personal and financial information of a subset of users was exposed to a third party impersonating a government agency. The attacker used a legitimate government agency domain email to submit fraudulent information requests, which were mistakenly treated as authentic. Exposed data included personally identifiable information such as names, addresses, dates of birth, copies of identification documents, and financial details including IBANs and transaction history. Revolut confirmed the breach, blocked the attacker’s email, and notified relevant authorities. The breach affected only a limited number of users, and Revolut’s systems and customer funds remain secure.
AI Analysis
Technical Summary
Revolut identified a sophisticated impersonation scam involving an unauthorized third party using a legitimate government agency domain email to fraudulently request user information. This led to the unintentional disclosure of personal and financial data of a subset of users. The compromised data included names, addresses, phone numbers, email addresses, dates of birth, occupation, copies of driver’s licenses and passports, verification selfies, and financial information such as IBANs, account statements, withdrawal records, and full transaction history including Bitcoin transactions. The company immediately blocked the attacker’s email address and informed relevant government, enforcement, data protection, and financial regulators. Revolut stated that only a small number of users were affected and that their systems and funds were not compromised.
Potential Impact
The breach exposed sensitive personal and financial information of a subset of Revolut users to an unauthorized third party impersonating a government agency. This exposure could lead to identity theft, financial fraud, and privacy violations for the affected individuals. However, Revolut’s systems and customer funds were not compromised, limiting the breach impact to data confidentiality rather than system integrity or availability.
Mitigation Recommendations
Revolut has blocked the attacker’s email address and notified the relevant government, enforcement, data protection, and financial regulatory agencies. Affected users have been directly informed and provided with support. No further action is indicated at this time as the breach was caused by a sophisticated impersonation scam and has been contained. Users should remain vigilant for phishing or fraud attempts using their exposed information.
Personal, Financial Info Exposed in Revolut Data Breach
Description
Revolut, a British fintech company, experienced a data breach where personal and financial information of a subset of users was exposed to a third party impersonating a government agency. The attacker used a legitimate government agency domain email to submit fraudulent information requests, which were mistakenly treated as authentic. Exposed data included personally identifiable information such as names, addresses, dates of birth, copies of identification documents, and financial details including IBANs and transaction history. Revolut confirmed the breach, blocked the attacker’s email, and notified relevant authorities. The breach affected only a limited number of users, and Revolut’s systems and customer funds remain secure.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Revolut identified a sophisticated impersonation scam involving an unauthorized third party using a legitimate government agency domain email to fraudulently request user information. This led to the unintentional disclosure of personal and financial data of a subset of users. The compromised data included names, addresses, phone numbers, email addresses, dates of birth, occupation, copies of driver’s licenses and passports, verification selfies, and financial information such as IBANs, account statements, withdrawal records, and full transaction history including Bitcoin transactions. The company immediately blocked the attacker’s email address and informed relevant government, enforcement, data protection, and financial regulators. Revolut stated that only a small number of users were affected and that their systems and funds were not compromised.
Potential Impact
The breach exposed sensitive personal and financial information of a subset of Revolut users to an unauthorized third party impersonating a government agency. This exposure could lead to identity theft, financial fraud, and privacy violations for the affected individuals. However, Revolut’s systems and customer funds were not compromised, limiting the breach impact to data confidentiality rather than system integrity or availability.
Defensive Guidance
Revolut has blocked the attacker’s email address and notified the relevant government, enforcement, data protection, and financial regulatory agencies. Affected users have been directly informed and provided with support. No further action is indicated at this time as the breach was caused by a sophisticated impersonation scam and has been contained. Users should remain vigilant for phishing or fraud attempts using their exposed information.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/personal-financial-info-exposed-in-revolut-data-breach/","fetched":true,"fetchedAt":"2026-09-14T13:16:39.834Z","wordCount":948}
Threat ID: 6aa7f3b755bf5e2cf51b4ca7
Added to database: 09/14/2026, 13:16:39 UTC
Last enriched: 09/14/2026, 13:16:51 UTC
Last updated: 09/15/2026, 03:45:44 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.