HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Revolut Discloses Unauthorized Release of Customer IDs and Financial Data to Impostor

Revolut confirmed that a fraudster posing as a government official obtained thousands of customer IDs, balances, and transaction histories. The incident underscores the importance of robust request‑verification controls for audit readiness.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 malwarebytes.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Revolut Discloses Unauthorized Release of Customer IDs and Financial Data to Impostor

What Happened — Revolut confirmed that a fraudster posing as a government official obtained customer identification numbers, account balances, and transaction histories. The impostor leveraged social‑engineering tactics to convince support staff to share the data, affecting thousands of users.

Why It Matters for Trust & Control Assurance

  • Highlights the need for rigorous identity‑verification controls around data‑request workflows – a core control‑area that continuous‑monitoring programs must evidence.
  • Demonstrates how a lapse in access‑control policies can create audit‑ready gaps across multiple frameworks (e.g., NIST CSF, ISO 27001).
  • Directly ties to Verisq’s Access Controls capability, which helps organizations capture, monitor, and prove that request‑validation procedures are consistently applied.

Who Is Affected – Financial services, digital‑banking platforms, and any organization handling sensitive customer financial data.

Recommended Actions

  1. Review and tighten verification procedures for any external data‑request, especially those claiming governmental authority.
  2. Implement continuous logging of data‑disclosure events and integrate them into your audit‑evidence repository.
  3. Conduct targeted security‑awareness training for support and compliance staff on social‑engineering detection.

Source: Malwarebytes Labs – Weekly Security Roundup

Technical Notes

  • Attack vector: Social engineering (impersonation of a government official).
  • Data types exposed: Customer IDs, account balances, transaction history.
  • No public vulnerability (CVE) associated; the breach stems from process failure.

Source: same as above

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/09/a-week-in-security-september-14-september-20

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →