Nearly 700 customers
Revolut, a leading European financial technology company, confirmed on September 12, 2026, that it suffered a data breach impacting nearly 700 customers. The breach was the result of a targeted social engineering attack where an unauthorized third party successfully impersonated a government agency. By deceiving the company, the attackers gained access to a trove of highly sensitive customer information, including not only personal data and bank account numbers but also copies of identity documents. Revolut stated it detected the attack, blocked the malicious access, and alerted the relevant government and enforcement agencies.
T1566 - Phishing)The core of this attack was deception. The threat actor likely researched Revolut's internal processes for handling Law Enforcement or Government Agency data requests. They then crafted a fraudulent request that appeared legitimate enough to bypass initial checks.
T1591 - Gather Victim Org Information)T1566.002 - Spearphishing Link)This incident is a stark reminder that the human element is often the weakest link in the security chain. Even technologically advanced companies like Revolut can be vulnerable to well-executed social engineering campaigns.
The exposure of this specific combination of data is particularly dangerous.
No specific Indicators of Compromise (IOCs), such as malicious domains or email addresses, were provided in the source articles.
Organizations can hunt for similar impersonation attempts by monitoring for the following:
From: and Reply-To: fieldsfbi-gov.com instead of fbi.gov).Train employees to recognize social engineering attempts and to follow strict verification procedures for sensitive data requests.
Implement and monitor Data Loss Prevention (DLP) policies to detect and alert on large or unusual exfiltration of PII.
Enforce the principle of least privilege to ensure that employees can only access the data absolutely necessary for their roles, limiting the scope of a potential insider error.
Revolut confirms it was the target of a sophisticated impersonation scam.
The breach was featured in a weekly news roundup.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.