Financexmagazine Revolut Data Breach Exposes 680 Customers via Social Engineering
Article Content
- •Revolut's breach affected 680 high-net-worth customers due to social engineering.
- •The hacker used a compromised government email to request sensitive KYC data.
- •IDScan's breach highlights risks in third-party KYC vendor dependencies.
In September 2026, Revolut confirmed a significant data breach affecting 680 customers, primarily high-net-worth individuals from Europe. The breach was initiated by a hacker posing as an Italian law enforcement agency, leveraging social engineering to request sensitive KYC information. The exposed data included passport copies, verification selfies, and transaction histories. The hacker, known as iamnotavillain, used blockchain analytics to identify targets and has since leaked some of the KYC information, demanding a $3 million ransom. This incident highlights vulnerabilities in third-party KYC vendors and the risks associated with trusting specific email domains. Additionally, IDScan, a KYC vendor, reported unauthorized access to identity information on its platform, further complicating the situation for financial institutions relying on its services. The surge in deepfake fraud attempts in the financial sector adds to the growing cybersecurity concerns.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track IDScan in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Exploitation Confirmed Citrix has confirmed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in its NetScaler ADC and Gateway products, both scoring 9.5 on the CVSS scale. These vulnerabilities are actively exploited in the wild, allowing unauthenticated attackers to execute arbitrary commands and potentially cause…