HomeIntelligenceBrief
BREACH BRIEF 🟠 High ThreatIntel

Revolut Discloses Social‑Engineering Data Breach Affecting Limited High‑Net‑Worth Customers

Financial Platform Was Socially Engineered Into Disclosing Sensitive Customer Data Digital financial platform Revolut is notifying customers that it suffered a data breach exposing their personal details after it fell for an official-looking "impersonation scam" involving a request for customer information sent using "a legitimate government agency domain email."

Verisq™ Intelligence · 📅 September 14, 2026 · 📰 databreachtoday.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
databreachtoday.com

Revolut Discloses Social‑Engineering Data Breach Affecting Limited High‑Net‑Worth Customers

What Happened

Revolut disclosed that a fraudster posing as an official from a compromised government email domain obtained a copy of a data‑request form. The company responded to the request and inadvertently released personal and financial details of a small, targeted group of customers. No unauthorized access to Revolut’s internal systems or theft of funds was reported.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates how a lapse in verification of external data‑requests can breach GDPR, DORA, and NIS2 obligations, highlighting the need for documented “request‑validation” controls in a continuous‑control‑assurance program.
  • Shows the importance of maintaining defensible evidence of incident‑response timelines (e.g., 72‑hour GDPR breach notification) to avoid regulatory fines.
  • Reinforces the value of regular audit‑ready testing of social‑engineering defenses, especially for high‑value customer segments.

Who Is Affected

  • Financial services firms (digital banks, neobanks, fintech platforms)
  • High‑net‑worth individual customers in the UK and EU
  • Third‑party data‑processing partners that handle identity‑verification documents

Recommended Actions

  • Review and tighten verification procedures for any external data‑request, especially those originating from government‑owned domains.
  • Validate that monitoring controls (e.g., DLP, anomalous‑request alerts) captured the outbound data flow and that logs are retained for audit.
  • Request a detailed incident‑response disclosure from Revolut to benchmark your own response playbooks.

Technical Notes

  • Attack vector: Social engineering via a spoofed official email request; no exploitation of software vulnerabilities.
  • CVEs: None reported.
  • Data types exposed: Customer name, date of birth, occupation, contact details, driver’s license or passport copy, selfie used for facial verification, account statements (IBAN, opening date, mobile‑wallet reference).

Source: https://www.databreachtoday.com/revolut-reveals-data-breach-tied-to-faked-official-request-a-32808

📰 Original Source
https://www.databreachtoday.com/revolut-reveals-data-breach-tied-to-faked-official-request-a-32808

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →