Revolut Discloses Social‑Engineering Data Breach Affecting Limited High‑Net‑Worth Customers
What Happened
Revolut disclosed that a fraudster posing as an official from a compromised government email domain obtained a copy of a data‑request form. The company responded to the request and inadvertently released personal and financial details of a small, targeted group of customers. No unauthorized access to Revolut’s internal systems or theft of funds was reported.
Why It Matters for Compliance & Audit Readiness
- Demonstrates how a lapse in verification of external data‑requests can breach GDPR, DORA, and NIS2 obligations, highlighting the need for documented “request‑validation” controls in a continuous‑control‑assurance program.
- Shows the importance of maintaining defensible evidence of incident‑response timelines (e.g., 72‑hour GDPR breach notification) to avoid regulatory fines.
- Reinforces the value of regular audit‑ready testing of social‑engineering defenses, especially for high‑value customer segments.
Who Is Affected
- Financial services firms (digital banks, neobanks, fintech platforms)
- High‑net‑worth individual customers in the UK and EU
- Third‑party data‑processing partners that handle identity‑verification documents
Recommended Actions
- Review and tighten verification procedures for any external data‑request, especially those originating from government‑owned domains.
- Validate that monitoring controls (e.g., DLP, anomalous‑request alerts) captured the outbound data flow and that logs are retained for audit.
- Request a detailed incident‑response disclosure from Revolut to benchmark your own response playbooks.
Technical Notes
- Attack vector: Social engineering via a spoofed official email request; no exploitation of software vulnerabilities.
- CVEs: None reported.
- Data types exposed: Customer name, date of birth, occupation, contact details, driver’s license or passport copy, selfie used for facial verification, account statements (IBAN, opening date, mobile‑wallet reference).
Source: https://www.databreachtoday.com/revolut-reveals-data-breach-tied-to-faked-official-request-a-32808