Personal, Financial Info Exposed in Revolut Data Breach

Revolut Faces Data Breach, Exposing Personal and Financial Info of Users Worldwide

British fintech giant Revolut is reeling after a data breach compromised the personal and financial information of some of its 80 million users worldwide. The incident highlights the ongoing threat posed by sophisticated social engineering tactics, where attackers pose as government agencies to extract sensitive data.

Revolut’s systems and customer funds are reportedly unaffected, but a subset of users received emails from an unauthorized third party claiming to be a government agency. The attackers successfully convinced Revolut’s security team that their request was legitimate, allowing them access to sensitive information. This included names, addresses, phone numbers, email addresses, dates of birth, occupation, copies of driver’s licenses and passports, as well as verification selfies.

The exposed financial data is equally concerning, with compromised accounts revealing IBANs, account statements, withdrawal records, and full transaction history – including Bitcoin transactions. The attackers’ ability to access this level of detail raises serious questions about the efficacy of Revolut’s security measures and its reliance on technical domain credentials from government agencies.

Revolut has confirmed that only a limited number of users were affected by the breach, but the company has not disclosed how many individuals are impacted. In response to the incident, Revolut blocked the attackers’ email address and notified both the relevant government agency and law enforcement bodies.

This breach serves as a stark reminder that even the most advanced security measures can be circumvented through sophisticated social engineering tactics. It’s essential for users of online financial services like Revolut to remain vigilant about phishing attempts and other types of social engineering attacks, which often rely on exploiting human psychology rather than technical vulnerabilities.

While Revolut has taken steps to address the breach, including notifying affected users directly, it’s clear that more needs to be done to prevent such incidents in the future. As our reliance on digital services grows, so too does the need for robust security measures and education about the risks of social engineering attacks.

For users of online financial services, this incident serves as a wake-up call to review their security settings and be cautious when interacting with unknown entities claiming to represent government agencies or other organizations. By staying informed and vigilant, we can mitigate the impact of such breaches and protect our sensitive data from falling into the wrong hands.


Source: SecurityWeek — 2026-09-14