Digital Bank Revolut Exposes Customer Data to Fake Government Agency

September 12, 2026 3 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: en.bloomingbit.io

Threat Risk: Medium
Victim: Revolut customers
Incident: Data breach via social engineering and spoofed government requests.
Impact: Exposure of passports, IBANs, and Bitcoin transaction histories for targeted users.
Attacker: Unidentified threat actors
Analysis: Attackers successfully impersonated a government entity to bypass Revolut’s internal verification processes. The resulting leak included high-value identity documents and financial records, increasing the risk of targeted phishing and fraud. This incident highlights a critical failure in identity verification for third-party data requests.
Recommendations: Implement multi-channel verification for all official government data requests.; Enhance internal security audits for third-party request validation protocols.; Alert high-net-worth customers to monitor for targeted social engineering attempts.
Source: Bloomingbit

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Latest Developments

Update — 2026-09-12 17:41 UTC

Data breach via fraudulent government requests. Exposure of sensitive customer information. Attackers successfully impersonated government officials to trick Revolut employees into releasing sensitive customer data. This highlights a critical failure in identity verification and request validation processes. The breach underscores the ongoing risk of high-level social engineering targeting financial institutions.

Corroborating source: reuters.com

Update — 2026-09-12 17:41 UTC

Data breach via fraudulent government requests. Exposure of sensitive customer personal and financial information. The breach highlights a critical vulnerability in how financial institutions verify high-level third-party requests. Attackers leveraged spoofed government communications to manipulate staff into releasing sensitive customer information. This incident underscores the ongoing efficacy of social engineering against well-resourced organizations.

Corroborating source: marketscreener.com

Update — 2026-09-12 17:41 UTC

Unauthorized disclosure of sensitive customer data via fraudulent government requests. Exposure of PII and identity documents, increasing the risk of identity theft for affected users. Threat actors leveraged a legitimate government email domain to deceive Revolut employees into disclosing customer PII. The breach highlights the risk of trusting email origins without secondary verification, even when the domain appears authentic. The stolen data, including passports and driver’s licenses, provides high utility for identity theft and fraud.

Corroborating source: lse.co.uk

Update — 2026-09-12 18:33 UTC

Customer data leak via a government domain scam. Unauthorized exposure of sensitive customer information. Attackers leveraged deceptive government-themed domains to orchestrate a scam that resulted in the unauthorized exposure of customer data. This incident highlights the effectiveness of authority-based social engineering when targeting financial institutions. The breach demonstrates how trust in official domains can be weaponized for data exfiltration.

Corroborating source: innovation-village.com

Update — 2026-09-12 18:45 UTC

Unauthorized disclosure of PII and financial history via a forged government request. Leak of sensitive identity documents and complete Bitcoin transaction histories for a limited group of users. Attackers leveraged a legitimate government email domain to deceive Revolut into releasing PII and Bitcoin transaction histories. While passwords and funds remained secure, the leaked identity documents and financial logs enable highly targeted phishing and social engineering. The incident underscores the risk of relying solely on email domains for identity verification of regulatory bodies.

Corroborating source: cryptoticker.io

Leave a Reply

Your email address will not be published. Required fields are marked *