Skip to main content

Revolut discloses data breach exposing financial info, passports

0
Medium
Breach
Published: 09/14/2026 (09/14/2026, 08:48:24 UTC)
Source: Bleeping Computer

Description

Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. [...]

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/14/2026, 09:17:39 UTC

Technical Analysis

Revolut experienced a data breach where an attacker impersonated a government agency by sending a request from an unauthorized email account using the official government agency's email domain. Due to valid domain authentication credentials, Revolut provided the requested customer data, which included personally identifiable information (full name, date of birth, occupation), contact details, identity documents (passport, driver's license), facial verification images, and detailed financial records such as account statements and transaction histories including Bitcoin transactions. The breach impacted a very limited number of customers, with indications that high net worth users were targeted. Revolut confirmed that its systems and customer funds remain secure and that it promptly blocked the attacker's address and alerted government, enforcement, data protection, and financial regulators.

Potential Impact

The breach exposed sensitive personal and financial information of an undisclosed, very limited number of Revolut customers, including identity documents and detailed transaction histories. This exposure increases the risk of identity theft, financial fraud, and targeted attacks against affected individuals. However, Revolut's operational systems and customer funds were not compromised. The breach may particularly impact high net worth customers, potentially increasing the severity of consequences for those individuals.

Defensive Guidance

Revolut has already blocked the attacker's email address and notified the relevant government agency, enforcement agencies, data protection authorities, and financial regulators. Customers affected have been informed. No further immediate action is required from customers or other parties as per Revolut's disclosures. Organizations should verify requests for sensitive data through multiple channels and implement strict verification processes to prevent similar social engineering attacks.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.93,"severitySource":"default","classifier":"rss-v2"}

Threat ID: 6aa7bba655bf5e2cf5d330ce

Added to database: 09/14/2026, 09:17:26 UTC

Last enriched: 09/14/2026, 09:17:39 UTC

Last updated: 09/15/2026, 04:10:45 UTC

Views: 26

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses