
The Revolut data breach has escalated into a serious cyber incident with potentially dangerous consequences for hundreds of customers worldwide. The British fintech company, used by over 80 million people worldwide, has confirmed that unauthorised parties gained access to confidential information after cybercriminals used a genuine government domain email address to send fake data requests.
The unauthorised parties gained access to addresses, names, dates of birth, email addresses and telephone numbers. An examination and analysis of reports from affected customers suggest that copies of passports and driving licences, verification selfies, bank statements, IBANs, withdrawal records and transaction histories – including Bitcoin transactions – may have been compromised.
Although the company has reported the incident to the FCA, the Information Commissioner’s Office, law enforcement agencies and data protection authorities, for a financial service of this calibre, this is not merely a ‘personal data breach’. The combination of documents, addresses, telephone numbers and transaction histories creates a ‘launchpad’ for further phishing, cryptocurrency theft, identity theft and targeted financial attacks, including those on crypto wallets.
According to Revolut, the attackers used a scheme involving social engineering to trick staff into treating fraudulent requests as legitimate demands from a government body. Although the company has not reported a breach of its database or the compromise of customers’ funds, and describes the number of victims as ‘limited/very limited’, media reports suggest that 680 customers received the malicious messages.
Revolut describes the incident as an ‘external impersonation scam’ and emphasises that it has not received any direct contact or ransom demands from those allegedly behind the attack, but some media outlets report that a group of attackers demanded 6,000 XMR – approximately $3 million (at the time the demand was made) – and threatened to hand over confidential data to criminal groups in the event of non-payment.
There is also a known case where one of the victims claimed that the individual who claimed to be in possession of their data demanded $50,000 for its deletion.
Despite the cryptocurrency trail, the main threat posed by this incident is not the theft of Bitcoin from accounts, but the fact that if the criminals have obtained documents, bank details and transaction histories, they can use this data for personalised attacks that will appear all the more convincing.
For the global financial world, the incident involving the leak of Revolut’s sensitive information served as a warning: modern fintech does not necessarily need to be hacked technically; it is enough to trick the system into trusting a fraudster. Thus, the weakest link may not be a server or an algorithm, but a person. In Revolut’s case, it was precisely the trust placed in a pseudo-governmental request that became the point of attack, and for customers, the consequences may last for much longer.