Threat Intelligence Brief
Curated summary with source attribution
Source: en.bloomingbit.io
Threat Risk: Medium
Victim: Revolut customers
Incident: Data breach via social engineering and spoofed government requests.
Impact: Exposure of passports, IBANs, and Bitcoin transaction histories for targeted users.
Attacker: Unidentified threat actors
Analysis: Attackers successfully impersonated a government entity to bypass Revolut’s internal verification processes. The resulting leak included high-value identity documents and financial records, increasing the risk of targeted phishing and fraud. This incident highlights a critical failure in identity verification for third-party data requests.
Recommendations: Implement multi-channel verification for all official government data requests.; Enhance internal security audits for third-party request validation protocols.; Alert high-net-worth customers to monitor for targeted social engineering attempts.
Source: Bloomingbit
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source
Latest Developments
Update — 2026-09-12 17:41 UTC
Data breach via fraudulent government requests. Exposure of sensitive customer information. Attackers successfully impersonated government officials to trick Revolut employees into releasing sensitive customer data. This highlights a critical failure in identity verification and request validation processes. The breach underscores the ongoing risk of high-level social engineering targeting financial institutions.
Corroborating source: reuters.com
Update — 2026-09-12 17:41 UTC
Data breach via fraudulent government requests. Exposure of sensitive customer personal and financial information. The breach highlights a critical vulnerability in how financial institutions verify high-level third-party requests. Attackers leveraged spoofed government communications to manipulate staff into releasing sensitive customer information. This incident underscores the ongoing efficacy of social engineering against well-resourced organizations.
Corroborating source: marketscreener.com
Update — 2026-09-12 17:41 UTC
Unauthorized disclosure of sensitive customer data via fraudulent government requests. Exposure of PII and identity documents, increasing the risk of identity theft for affected users. Threat actors leveraged a legitimate government email domain to deceive Revolut employees into disclosing customer PII. The breach highlights the risk of trusting email origins without secondary verification, even when the domain appears authentic. The stolen data, including passports and driver’s licenses, provides high utility for identity theft and fraud.
Corroborating source: lse.co.uk
Update — 2026-09-12 18:33 UTC
Customer data leak via a government domain scam. Unauthorized exposure of sensitive customer information. Attackers leveraged deceptive government-themed domains to orchestrate a scam that resulted in the unauthorized exposure of customer data. This incident highlights the effectiveness of authority-based social engineering when targeting financial institutions. The breach demonstrates how trust in official domains can be weaponized for data exfiltration.
Corroborating source: innovation-village.com
Update — 2026-09-12 18:45 UTC
Unauthorized disclosure of PII and financial history via a forged government request. Leak of sensitive identity documents and complete Bitcoin transaction histories for a limited group of users. Attackers leveraged a legitimate government email domain to deceive Revolut into releasing PII and Bitcoin transaction histories. While passwords and funds remained secure, the leaked identity documents and financial logs enable highly targeted phishing and social engineering. The incident underscores the risk of relying solely on email domains for identity verification of regulatory bodies.
Corroborating source: cryptoticker.io
Update — 2026-09-12 19:27 UTC
Data breach triggered by fraudulent government requests. Unauthorized exposure of sensitive customer data. Threat actors successfully impersonated government officials to deceive Revolut into releasing private user data. This incident highlights a critical weakness in the verification processes used for official legal and regulatory requests. It demonstrates how social engineering can bypass technical controls by targeting corporate compliance workflows.
Corroborating source: menafn.com
Update — 2026-09-12 19:27 UTC
Sensitive customer data was leaked after employees fell for a sophisticated impersonation scam. Exposure of passports, driver’s licenses, transaction histories, and IBANs for a limited number of users. This incident highlights a critical failure in data verification processes where a legitimate government email domain was used to deceive employees. By leveraging an authorized domain, attackers bypassed traditional trust filters to request high-value PII and financial records. The breach demonstrates that domain legitimacy does not equal request authenticity.
Corroborating source: cybernews.com