Revolut

Sep 2026 · Graded Attested · Financial Services · Beyond the filings
RevolutSep 2026
Revolut released customer records to someone impersonating a government agency from that agency's own email domain. No hack required, just a trusted sender field. Passports, birth dates, addresses, KYC selfies, and financial histories were the haul, but Revolut has declared that the number of impacted customers is small. The extortion group disputes that and has been releasing files on Telegram to make their case. "It's just a few rich people's passports" doesn't sound reassuring coming from a massive global bank.
Revolut discloses data breach exposing financial info, passports
Initial attack type phishing or social engineering confirmed · Impact data theft confirmed + data extortion
Not yet quantified
AAttestedFinancial Services
About this record
This incident is beyond the filings: attributed to a company statement, a regulator or court record, or a news report, and graded Attested or Inferred. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.
← The complete Beyond the Filings ledger ← Back to the index