Find notable cyber news and cases, enriched with sources, timelines, and signals.

Revolut hit by cyberattack

Incident
First reported
Last updated
Happening score
H score 17
2 unique sources, 2 articles

Summary

Hide ▲

Revolut disclosed a data breach after a threat actor impersonated a government agency and obtained customer information through email. The exposed data included identity details, contact information, identity documents, verification selfies, account statements, IBAN numbers, withdrawal records, and full transaction history. Revolut said the breach affected a very limited number of customers, while systems and customer funds are unaffected. The company said it blocked the address and notified government, enforcement, data protection, and financial regulators.

Related Happenings

Revolut customer data breach exposing identity and financial records

Data Leak
H score37 First: 14.09.2026 11:48 Last: 14.09.2026 11:48 Sources 1

How related: The compromised data reportedly includes full names, dates of birth, residential addresses, phone numbers, email addresses and occupations, along with copies of government ID documents (such as passports and driver's licenses) and verification selfies.

About this happening: Revolut disclosed a data breach that exposed customer information after an attacker impersonated a government agency and obtained data through email. The exposed set i...

23AndMe hit by network compromise

Incident
H score55 First: 16.07.2026 16:47 Last: 16.07.2026 16:47 Sources 1

About this happening: 23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...

Latest development: 17.07.2026 17:30

23andMe reached an $18m settlement with a coalition of 42 US attorneys general over the 2023 credential stuffing breach, and the agreement adds new data protection requirements for 23andMe customer data and TTAM Research.

Timeline

  1. 14.09.2026 11:48 3 articles · 2h ago

    Revolut discloses customer data breach after government-agency impersonation

    Initial Disclosure

    Revolut disclosed a data breach after a threat actor impersonating a government agency obtained customer information via email using the agency's domain and valid domain authentication credentials. The data sent to the threat actor included identity details, contact details, identity documents, facial verification images, account statements with IBAN numbers, withdrawal records, and full transaction history, while Revolut said the breach affected a very limited number of customers and that Revolut systems and customer funds are unaffected. Revolut said it blocked the address after detection and alerted the relevant government agency, enforcement agencies, data protection, and financial regulators.

    Show sources