Revolut Data Breach Exposes Customer PII and ID Documents

Revolut Data Breach Exposes Data of Nearly 700 Customers

HIGH
September 20, 2026
5m read
Data BreachPhishingThreat Intelligence

Impact Scope

People Affected

Nearly 700 customers

Industries Affected

FinanceTechnology

Related Entities

Full Report

Executive Summary

Revolut, a leading European financial technology company, confirmed on September 12, 2026, that it suffered a data breach impacting nearly 700 customers. The breach was the result of a targeted social engineering attack where an unauthorized third party successfully impersonated a government agency. By deceiving the company, the attackers gained access to a trove of highly sensitive customer information, including not only personal data and bank account numbers but also copies of identity documents. Revolut stated it detected the attack, blocked the malicious access, and alerted the relevant government and enforcement agencies.

Threat Overview

  • Victim: Revolut, a major fintech firm.
  • Attack Vector: Social Engineering / Impersonation. This was not a technical exploit of a software vulnerability, but rather a manipulation of human processes. The attacker posed as a legitimate government agency making a data request. This is a form of business email compromise (BEC) or spear phishing, targeting internal company procedures. (T1566 - Phishing)
  • Impacted Population: Nearly 700 customers.
  • Exposed Data: The breach exposed a wide range of sensitive data, creating a significant risk for the affected individuals. The compromised data includes:
    • Full names
    • Dates of birth
    • Postal and email addresses
    • Phone numbers
    • Bank account numbers
    • Copies of identity documents (passports, driver's licenses)

Technical Analysis

The core of this attack was deception. The threat actor likely researched Revolut's internal processes for handling Law Enforcement or Government Agency data requests. They then crafted a fraudulent request that appeared legitimate enough to bypass initial checks.

  1. Reconnaissance: The attacker likely studied Revolut's public information and possibly identified employees or departments responsible for handling official data requests. (T1591 - Gather Victim Org Information)
  2. Impersonation: The attacker created and sent a request, likely via email, that convincingly mimicked one from a real government agency. This could involve using a typosquatted domain or a compromised email account from a legitimate entity. (T1566.002 - Spearphishing Link)
  3. Execution: A Revolut employee or automated system processed the fraudulent request, believing it to be legitimate, and provided the requested data to the attacker.
  4. Exfiltration: The attacker received the sensitive customer data.

This incident is a stark reminder that the human element is often the weakest link in the security chain. Even technologically advanced companies like Revolut can be vulnerable to well-executed social engineering campaigns.

Impact Assessment

The exposure of this specific combination of data is particularly dangerous.

  • Identity Theft: With names, dates of birth, addresses, and copies of official ID documents, attackers have a complete kit to perpetrate sophisticated identity theft. They could open new lines of credit, file fraudulent tax returns, or impersonate the victims in other transactions.
  • Financial Fraud: Direct access to bank account numbers can facilitate fraudulent transactions.
  • Targeted Phishing: Attackers can use the stolen information to launch highly convincing phishing attacks against the affected customers, pretending to be Revolut and citing specific personal details to gain trust.
  • Regulatory Fines: As a European company, Revolut will face scrutiny under GDPR, and could face significant fines for the breach.

IOCs — Directly from Articles

No specific Indicators of Compromise (IOCs), such as malicious domains or email addresses, were provided in the source articles.

Cyber Observables — Hunting Hints

Organizations can hunt for similar impersonation attempts by monitoring for the following:

Type
Email Header
Value
Mismatched From: and Reply-To: fields
Description
A common sign of email spoofing or impersonation.
Type
Domain
Value
Typosquatted or lookalike domains
Description
Monitor for incoming emails from domains that are slight variations of legitimate partner or government agency domains (e.g., fbi-gov.com instead of fbi.gov).
Type
Other
Value
Unusual data requests
Description
Flag internal requests for bulk customer data, especially if they originate from an unusual source or deviate from standard procedure.

Detection & Response

  • Process Verification: Implement a strict, multi-step verification process for all external requests for sensitive data, especially those from government or law enforcement. This should include an out-of-band confirmation step, such as a phone call to a known, verified number for the requesting agency.
  • Employee Training: Continuously train employees, particularly those in roles that handle sensitive data, to recognize the signs of social engineering and impersonation. Empower them to question and escalate any suspicious requests.
  • DLP Solutions: Data Loss Prevention (DLP) tools can be configured to alert on or block the transmission of large volumes of PII outside the organization, providing a technical backstop to a human error.

Mitigation

  • Data Minimization: Only collect and retain customer data that is absolutely necessary. The less data you hold, the lower the impact of a breach.
  • Access Controls: Strictly limit access to bulk customer data. Employees should only have access to the information required to perform their specific job functions.
  • Strong Authentication: While not the primary vector here, ensuring all internal systems require MFA can prevent an attacker who has stolen employee credentials from easily accessing data.
  • Response Protocol: Revolut's quick action to block the address and alert agencies is a good example of a prepared response. All organizations should have a well-defined incident response plan for data breaches.

Timeline of Events

1
September 12, 2026
Revolut confirms it was the target of a sophisticated impersonation scam.
2
September 20, 2026
The breach was featured in a weekly news roundup.
3
September 20, 2026
This article was published

MITRE ATT&CK Mitigations

Train employees to recognize social engineering attempts and to follow strict verification procedures for sensitive data requests.

Audit

M1047enterprise

Implement and monitor Data Loss Prevention (DLP) policies to detect and alert on large or unusual exfiltration of PII.

Enforce the principle of least privilege to ensure that employees can only access the data absolutely necessary for their roles, limiting the scope of a potential insider error.

Timeline of Events

1
September 12, 2026

Revolut confirms it was the target of a sophisticated impersonation scam.

2
September 20, 2026

The breach was featured in a weekly news roundup.

Sources & References

This Week's Top Five Stories in Cyber
Cyber Magazine (cybermagazine.com) September 19, 2026
Recent Data Breaches (Sep 2026): Latest Incidents - Scan My Shadow
Scan My Shadow (scanmyshadow.com) September 20, 2026
Week in review: Cisco patches exploited email gateway 0-day, Revolut breach
Help Net Security (helpnetsecurity.com) September 20, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

RevolutData BreachFintechSocial EngineeringImpersonationPIIGDPR

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.