Find notable cyber news and cases, enriched with sources, timelines, and signals.

Revolut customer data breach exposing identity and financial records

Data Leak
First reported
Last updated
Happening score
H score 37
2 unique sources, 2 articles

Summary

Hide ▲

Revolut disclosed a data breach that exposed customer information after an attacker impersonated a government agency and obtained data through email. The exposed set included identity documents, facial verification images, and financial records such as IBANs, withdrawal records, and transaction history. Revolut said the breach affected a very limited number of customers and that its systems and customer funds are unaffected.

Related Happenings

Revolut hit by cyberattack

Incident
H score17 First: 14.09.2026 11:48 Last: 14.09.2026 11:48 Sources 1

How related: Speaking to Infosecurity on September 14, a Revolut spokesperson said an unauthorized third party submitted “fraudulent requests for information” using a “legitimate government agency domain email”.

About this happening: Revolut disclosed a data breach after a threat actor impersonated a government agency and obtained customer information through email. The exposed data included identi...

23AndMe hit by network compromise

Incident
H score55 First: 16.07.2026 16:47 Last: 16.07.2026 16:47 Sources 1

About this happening: 23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...

Latest development: 17.07.2026 17:30

23andMe reached an $18m settlement with a coalition of 42 US attorneys general over the 2023 credential stuffing breach, and the agreement adds new data protection requirements for 23andMe customer data and TTAM Research.

Timeline

  1. 14.09.2026 11:48 3 articles · 2h ago

    Revolut discloses customer data breach after government-agency impersonation request

    Initial Disclosure

    Revolut disclosed that an unauthorized email account sent a request for customer information using a government agency's domain and valid domain authentication credentials, leading the company to share data from an undisclosed number of customers with a threat actor. The exposed information included identity details, contact details, identity document copies, facial verification images, account statements with IBAN numbers, withdrawal records, and full transaction history, while Revolut said its systems and customer funds were unaffected and that it blocked the address and alerted the relevant government agency and regulators.

    Show sources