Technadu Revolut Data Breach Linked to Fraudulent Government Requests
Article Content
- •Fraudsters impersonated a government agency to obtain sensitive customer data.
- •Approximately 680 customers were affected, with no U.S. customers involved.
- •Revolut has taken steps to block the fraudulent email and alert authorities.
Revolut confirmed a data breach affecting a limited number of customers due to fraudsters posing as a government agency. The attackers utilized a legitimate government email domain to submit fraudulent requests for sensitive customer information, including passports, driver's licenses, and account details. The breach impacted approximately 680 customers, primarily in Europe, with no U.S. customers affected. Revolut has blocked the fraudulent email address and notified relevant authorities. The incident highlights vulnerabilities in compliance processes that may not adequately verify the legitimacy of data requests. A ransom demand of $3 million was made by a group claiming responsibility for the attack. The company has not disclosed how it detected the fraud or the specific government agency involved.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Qilin, PhantomRaven and Brevo in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
SonicWall SMA1000 Faces Critical Zero-Day Exploitation SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access…