Heise.De Revolut Data Breach: Hackers Exploit Government Domain for Customer Info Theft
Article Content
- •Attackers used a legitimate government email domain to exploit Revolut's compliance process.
- •Sensitive data of a few hundred customers, including identity documents, was leaked.
- •Revolut's IT systems and customer funds remain unaffected by the breach.
Revolut has confirmed a data breach where attackers used a legitimate government email domain to request sensitive customer information. The incident targeted high-net-worth individuals, leading to the exposure of personal data including identity documents and transaction details. Revolut stated that the breach was a result of a 'sophisticated external fraud attempt' and that the attackers exploited the bank's compliance mechanisms. Although the breach affected a few hundred customers, Revolut emphasized that its IT systems and customer funds remain secure. The company has blocked the fraudulent email address and reported the incident to law enforcement. The breach was discovered during a subsequent inquiry by Revolut to the government agency. The attackers have reportedly begun extorting victims by threatening to publish stolen data. Revolut is currently addressing the situation and has contacted affected customers directly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Revolut in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…