Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Personal, Financial Info Exposed in Revolut Data Breach

The company unintentionally disclosed users’ information to a third party impersonating a government agency.

Revolut data breach

British fintech giant Revolut is notifying a subset of users that their personal and financial information was compromised in a data breach.

Based in London, the neobank and financial technology company provides banking and investment services to over 80 million users in 160 countries and regions.

Late last week, the company informed a small number of users that their personally identifiable information (PII) was exposed to a third party posing as a government agency.

The exposed data, it said in emails to the affected users, included names, addresses, phone numbers, email addresses, dates of birth, occupation, copies of driver’s licenses and passports, and verification selfies.

Financial information, including IBANs, account statements, withdrawal records, and full transaction history, including Bitcoin, was also exposed.

The request carried valid technical domain credentials and was treated as an authentic agency inquiry. All financial institutions must comply with legal requests from law enforcement and government agencies.

Advertisement. Scroll to continue reading.

Responding to a SecurityWeek inquiry, a Revolut spokesperson confirmed the incident.

“Revolut recently identified a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information.

After discovering the data breach, the company immediately blocked the attackers’ email address and notified the “relevant government agency as well as enforcement agencies, data protection, and financial regulators,” the spokesperson added.

According to Revolut, only a subset of its users was affected. However, the company did not say how many individuals were impacted.

“Revolut systems and customer funds are unaffected. We have contacted the limited number of impacted individuals directly to inform them and provide support,” Revolut’s representative said.

Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Related: Telus Warns Customers of Account Breaches

Related: Phishing Research Challenges Conventional Security Awareness Testing

Related: Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

Patrick McKinney has joined Turing as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.