HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Revolut Fintech Breach: Impersonated Government Email Leaks Customer Identity Data

Revolut disclosed that an attacker posing as a government agency used a spoofed agency‑domain email to obtain sensitive customer records, including identity documents and transaction histories. The breach highlights gaps in email authentication and data‑access verification that continuous‑control‑assurance programs must address for audit readiness.

Verisq™ Intelligence · 📅 September 14, 2026 · 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
helpnetsecurity.com

Revolut Fintech Breach: Impersonated Government Email Leaks Customer Identity Data

What Happened – On 12 September 2026 Revolut confirmed that an attacker posing as a government agency used a legitimate‑looking agency‑domain email address to request and receive sensitive customer records. The disclosed data includes birth dates, addresses, phone numbers, passport and driver‑license scans, verification selfies, account statements, and transaction histories (including cryptocurrency activity).

Why It Matters for Trust & Control Assurance

  • This incident exemplifies a failure of identity‑verification and communication‑authentication controls, a core control area that continuous‑control‑assurance programs are built to monitor and evidence.
  • Robust logging of outbound requests and a documented incident‑response workflow provide the defensible audit trail regulators (e.g., GDPR) expect after a data‑exposure event.
  • The scenario underscores the need for continuous monitoring of email authentication mechanisms (DMARC, SPF, DKIM) and for policies that require out‑of‑band verification of any request for customer data.

Who Is Affected – Financial services and payments providers, especially those handling high‑net‑worth clientele; downstream partners that rely on Revolut’s data‑processing practices.

Recommended Actions

  • Map the breach to the control objective “Verify the authenticity of external communications and enforce least‑privilege data access.”
  • Review and tighten email authentication (DMARC, SPF, DKIM) and enforce a dual‑approval process for any request that involves personal data export.
  • Update incident‑response playbooks to include evidence‑preservation steps for phishing‑based data‑exfiltration.
  • Conduct a targeted audit of data‑access logs for the period surrounding the incident and retain that evidence for regulator review.

Source: Help Net Security

Technical Notes – Attack vector: phishing / social engineering using a spoofed government‑domain email address. No vulnerability in Revolut’s platform was disclosed; the breach stemmed from successful impersonation. Exfiltrated data: personally identifiable information (PII), identity documents, verification selfies, account statements, and cryptocurrency transaction records. Source: same as above

📰 Original Source
https://www.helpnetsecurity.com/2026/09/14/revolut-data-breach-privacy/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →