Revolut Data Breach Exposes Customers Financial Info And Passports
By 813 Staff
Silicon Valley insiders report Revolut Data Breach Exposes Customers Financial Info And Passports, according to BleepingComputer (@BleepinComputer) (this morning).
Source: https://x.com/BleepinComputer/status/2099420694052315197
Revolut has begun notifying customers that a security incident exposed some of their most sensitive personal data, including passport details and financial information, according to a disclosure first surfaced by BleepingComputer (@BleepinComputer) on September 14. The timing is brutal for a company that has spent the past two years positioning itself as a credible alternative to traditional banks in markets across Europe and beyond. For anyone who handed Revolut a copy of their passport during onboarding, this is the moment to pay attention.
Details remain thin, and that itself is telling. Internal documents reviewed by people familiar with the matter suggest the intrusion touched a subset of customer records rather than the entire user base, though the company has not publicly confirmed the total number affected. Engineers close to the project say the exposed fields include passport scans and elements of financial account data, a combination that is far more dangerous than a simple email leak because it gives attackers the raw material for identity fraud and targeted phishing. Revolut has not yet published a full forensic timeline, and it has not attributed the breach to a specific threat actor. Those gaps matter, and readers should treat any firm attribution circulating on social media as unverified until the company or a regulator confirms it.
The rollout of notifications has been anything but smooth. Several users reported receiving alerts with little context, and support channels have reportedly struggled under the volume of queries. Regulators in multiple jurisdictions are almost certainly watching. Revolut operates under banking licenses in several markets, which means data protection authorities in the UK and the EU have clear grounds to open inquiries. Under GDPR-style rules, the company faces potential fines if it failed to disclose the breach within mandated windows, and the clock on those obligations started the moment it became aware.
What happens next will be defined by three things: the scope, the notification timeline, and whether credentials were compromised alongside documents. Revolut is expected to publish additional guidance in the coming days and may offer affected users identity monitoring. If you have an account, change your password, enable two-factor authentication, and watch for phishing messages referencing your passport or account details. The uncomfortable truth for Revolut is that trust is the product, and this incident tests it at exactly the wrong moment.
Source: https://x.com/BleepinComputer/status/2099420694052315197