Revolut: Revolut’s data breach shows institutions can be at risk even when not directly compromised

Revolut: Revolut’s data breach shows institutions can be at risk even when not directly compromised

Revolut Data Breach Exposes 680 Customers in Sophisticated Social Engineering Attack

Revolut, one of Europe’s leading digital financial services providers, suffered a data breach after cybercriminals impersonated government officials using a compromised legitimate email account. The attackers, posing as law enforcement or regulatory authorities, convinced Revolut to disclose sensitive customer information including passport details, identity documents, home addresses, bank account numbers, and cryptocurrency activity affecting approximately 680 individuals.

Unlike traditional breaches, the attackers did not infiltrate Revolut’s core systems. Instead, they exploited trust in official communication channels, demonstrating how financial institutions remain vulnerable even when their internal security remains intact. The fraudulent requests, sent over several months, targeted customers with significant cryptocurrency holdings, primarily in Switzerland and France, though data from 31 other European countries was also involved.

The hackers later demanded a ransom, threatening to publish the stolen information. Revolut blocked the fraudulent email address, reported the incident to authorities, and confirmed that its internal systems and customer funds were not compromised. The attack originated from a hijacked Italian government email system used for secure legal communications, underscoring the growing threat of credential-based impersonation.

The incident highlights a shift in cybercriminal tactics, where social engineering and AI-enabled fraud bypass traditional security measures. Reports from the Federal Reserve and Visa indicate a rise in such attacks, with scams accounting for nearly $1 billion in fraudulent activity in late 2025. For digital banks like Revolut, balancing responsiveness to legitimate regulatory requests with fraud prevention has become increasingly complex.

The UK’s Information Commissioner’s Office (ICO) has launched an investigation into the breach, though no regulatory violations have been confirmed. The ICO’s guidance emphasizes the need for robust breach detection and timely notification of affected individuals when high-risk data is exposed.

The breach also raises broader questions about regulatory adaptation to evolving threats. As criminals leverage deepfakes, synthetic identities, and AI-generated messages, financial institutions may need to adopt decentralized identity verification, blockchain-based credentials, and hyperscale AI for real-time threat detection. The Bank for International Settlements (BIS) has urged regulators to evolve frameworks alongside technological advancements, ensuring defenses keep pace with emerging risks.

The incident serves as a reminder that security must extend beyond perimeter defenses, requiring stricter verification of external requests and controlled disclosure of sensitive data.

Source: https://thedigitalbanker.com/revoluts-data-breach-shows-institutions-can-be-at-risk-even-when-not-directly-compromised/

Revolut cybersecurity rating report: https://www.rankiteo.com/company/revolut

"id": "REV1789562336",
"linkid": "revolut",
"type": "Breach",
"date": "7/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '680',
                        'industry': 'FinTech/Banking',
                        'location': 'Europe (Headquartered in UK)',
                        'name': 'Revolut',
                        'type': 'Digital Financial Services Provider'}],
 'attack_vector': 'Social Engineering (Impersonation of Government Officials)',
 'data_breach': {'data_exfiltration': 'Yes',
                 'number_of_records_exposed': '680',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Passport details',
                                              'Identity documents',
                                              'Home addresses',
                                              'Bank account numbers',
                                              'Cryptocurrency activity']},
 'description': 'Revolut suffered a data breach after cybercriminals '
                'impersonated government officials using a compromised '
                'legitimate email account. The attackers convinced Revolut to '
                'disclose sensitive customer information including passport '
                'details, identity documents, home addresses, bank account '
                'numbers, and cryptocurrency activity affecting approximately '
                '680 individuals. The fraudulent requests targeted customers '
                'with significant cryptocurrency holdings, primarily in '
                'Switzerland and France, though data from 31 other European '
                'countries was also involved.',
 'impact': {'brand_reputation_impact': 'High',
            'data_compromised': 'Passport details, identity documents, home '
                                'addresses, bank account numbers, '
                                'cryptocurrency activity',
            'identity_theft_risk': 'High',
            'legal_liabilities': 'Potential (under investigation by UK ICO)',
            'payment_information_risk': 'High'},
 'initial_access_broker': {'data_sold_on_dark_web': 'Potential',
                           'entry_point': 'Compromised Italian government '
                                          'email system',
                           'high_value_targets': 'Customers with significant '
                                                 'cryptocurrency holdings',
                           'reconnaissance_period': 'Several months'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Security must extend beyond perimeter defenses; stricter '
                    'verification of external requests and controlled '
                    'disclosure of sensitive data are required. The incident '
                    'highlights the growing threat of social engineering and '
                    'AI-enabled fraud.',
 'motivation': 'Financial gain (ransom demand, potential sale of data on dark '
               'web)',
 'post_incident_analysis': {'corrective_actions': 'Blocked fraudulent email '
                                                  'address; reported incident '
                                                  'to authorities',
                            'root_causes': 'Exploitation of trust in official '
                                           'communication channels; '
                                           'compromised legitimate email '
                                           'account'},
 'ransomware': {'data_exfiltration': 'Yes', 'ransom_demanded': 'Yes'},
 'recommendations': ['Adopt decentralized identity verification',
                     'Implement blockchain-based credentials',
                     'Use hyperscale AI for real-time threat detection',
                     'Enhance verification processes for external requests'],
 'references': [{'source': 'Federal Reserve and Visa reports'},
                {'source': 'Bank for International Settlements (BIS)'},
                {'source': 'UK Information Commissioner’s Office (ICO)'}],
 'regulatory_compliance': {'legal_actions': 'Under investigation by UK ICO',
                           'regulatory_notifications': 'Yes'},
 'response': {'containment_measures': 'Blocked fraudulent email address',
              'law_enforcement_notified': 'Yes'},
 'threat_actor': 'Cybercriminals',
 'title': 'Revolut Data Breach Exposes 680 Customers in Sophisticated Social '
          'Engineering Attack',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Compromised legitimate email account (Italian '
                            'government email system)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.