Fintech giant Revolut confirms it suffered a customer data breach and hackers faked emergency data requests from law enforcement agencies

📅 2026-09-12

Abstract:

Revolut, the well-known British financial technology giant, officially confirmed that the company suffered a fraud attack by hackers using fake emergency data requests (EDRs) from government and law enforcement agencies, resulting in the leakage of some customers' personal privacy data. This cyber security incident once again exposed the risk of new social engineering attacks on the compliance and legal review channels of technology companies. The regulatory agencies and data protection authorities involved in the case have now intervened in the investigation. Forged government law enforcement letters were secretly revealed, and digital banking giant Revolut confirmed that a customer data breach had occurred

revolut.webp

Digital banking giant Revolut recently confirmed that it suffered a security incident involving a customer personal data leak. The attackers used highly simulated fake government and law enforcement agency legal substantiation requests to successfully bypass internal compliance and review processes and illegally obtain sensitive information of some customers.

According to information disclosed by Revolut to affected users and regulatory agencies, the hacker group sent emergency information disclosure instructions to the platform's data request processing team by forging official letters, emails and electronic credentials from legitimate government departments or law enforcement agencies. This type of forged request was extremely deceptive in appearance and format, causing relevant internal support and legal compliance personnel to make misjudgments during the verification process, and ultimately processed and released the background data of some accounts in compliance with regulations.

The leaked data mainly involves basic personally identifiable information of some affected customers, including full names, registered email addresses, phone numbers, and some transaction history records and account metadata. Revolut emphasized that the core financial security credentials such as users’ login credentials, passwords, dynamic PIN codes, and bank card numbers have not been affected. User funds and assets on the platform are absolutely safe, and the underlying encryption architecture of the system itself has not been technically breached.

After the internal security mechanism captured the abnormal data flow pattern, Revolut immediately launched an emergency response process, blocked relevant attack links, and launched a comprehensive retrospective audit of all pending and historical backlogged law enforcement assistance investigation applications. At the same time, the agency has officially reported the incident to the data protection regulators and law enforcement agencies of the relevant countries, and is cooperating with professional cybersecurity agencies to track down the specific entities or hacker groups behind the forged requests.

This incident once again exposed the risk of a new type of social engineering attack on financial technology companies - that is, bypassing technical firewalls and directly targeting non-technical compliance channels for handling legal and government affairs with precise deception. In order to prevent similar incidents from happening again, Revolut said it is comprehensively reconstructing its legal substantiation and review system, introducing a more stringent multi-party offline verification mechanism, and upgrading its automated anti-fraud and credential cross-verification processes to deal with increasingly complex fake government authorization attacks. At present, affected users have received exclusive security notifications one after another. The company recommends that relevant users be more vigilant in the near future and pay attention to detecting secondary phishing or SMS fraud implemented by fake official customer service personnel.

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet