HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Revolut Discloses Customer IDs and Financial Data to Impersonated Government Email

Revolut supplied personal IDs, selfies, and account statements for a limited number of customers to an unauthorized party after responding to a spoofed government‑agency email request. The breach underscores the need for verified data‑request controls and audit‑ready evidence of handling personal information.

Verisq™ Intelligence · 📅 September 14, 2026 · 📰 malwarebytes.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
malwarebytes.com

Revolut Discloses Customer IDs and Financial Data to Impersonated Government Email

What Happened – Revolut confirmed that it supplied personal identification documents, selfies, and account statements for a limited set of customers to an unauthorized party after responding to a fraudulent request that appeared to originate from a legitimate government‑agency email domain. The incident was a social‑engineering impersonation, not a technical intrusion, and no customer funds were directly taken.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of inadequate verification of external data‑request channels – a control‑area that continuous monitoring and auditable evidence can mitigate.
  • Highlights the need for documented security‑awareness training and incident‑response playbooks that capture social‑engineering attempts as part of a defensible audit trail.
  • Aligns with the control objective of “Verified third‑party data requests and secure handling of personal information,” which maps to multiple frameworks (e.g., NIST CSF 2.0).

Who Is Affected – Global digital‑banking platforms, fintech providers, and any organization that processes personal identification data on behalf of customers.

Recommended Actions

  • Review and harden verification procedures for any external request that involves personal or financial data.
  • Institute regular security‑awareness training that includes realistic impersonation scenarios.
  • Ensure all data‑request activities are logged, reviewed, and retained as audit evidence.
  • Conduct a control‑gap assessment against the “verified third‑party request” objective and remediate any deficiencies.

Source: Malwarebytes Labs

Technical Notes – The attack leveraged a spoofed email address on a legitimate government domain to bypass Revolut’s request‑validation process. No malware, CVE, or system exploit was involved; the breach vector was purely social engineering. Exposed data included dates of birth, addresses, passport and driver’s‑license scans, verification selfies, and transaction histories. Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/09/revolut-gave-customer-ids-and-financial-data-to-a-government-impostor

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →