Skip to content
Revolut Data Breach: Infostealers Exploit Social Engineering Tactics

Revolut Data Breach: Infostealers Exploit Social Engineering Tactics

First seen 15 Sep 2026, 18:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 19:55 UTC
  • Revolut's customer data breach involved unauthorized access to sensitive information.
  • The attack employed infostealers and social engineering tactics over five months.
  • Revolut has notified authorities and is investigating the incident's impact.

Revolut confirmed that unauthorized third parties accessed sensitive customer data, including passports and driving licenses, through fraudulent requests sent from a legitimate government email domain. The attack was executed using infostealers to compromise employee email accounts, allowing the hacker to send fake requests to Revolut's Lithuanian subsidiary. Over a five-month period, the hacker maintained control of the compromised inbox, sending multiple fraudulent requests without raising suspicion. Revolut has alerted relevant authorities and is assessing the impact on its 80 million global customers. The incident highlights the critical distinction between verifying information and authenticating the identity behind requests, emphasizing the risks of social engineering attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-04-15
Initial fraudulent request sent
The hacker sent a fake request to Revolut using a compromised email account, posing as the Italian government.
Infostealers
2026-09-15
Revolut confirms data breach
Revolut announced that sensitive customer data was accessed by unauthorized parties through fraudulent requests.
Cirmagazine

More articles in this cluster (2)

Following this threat?

Track Revolut in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed