Digital hook showing data breach at fintech

Data Breach at Fintech Firm Revolut Exposes Personal and Financial Information of High-Net-Worth Individuals

A data breach at the British bank and fintech firm Revolut, stemming from fake government requests, has exposed its customers’ personal information. The British bank disclosed the information to the third party after receiving emails from a potentially hacked legitimate government email domain.

Operating in 160 countries and registered in 30 as a bank, Revolut serves over 800,000 enterprise customers and over 80 million individuals. Its services include online banking, currency conversion, cryptocurrency exchange, and insurance services through its mobile app.

Revolut data breach leaks personal information of nearly 700 people

The Revolut breach exposed documents uploaded as part of the company’s verification process. Details leaked included drivers’ licenses, account statements, bank and Bitcoin transactions and histories, names, dates of birth, email addresses, phone numbers, International Banking Numbers (IBANs), and verification selfies from the know your customer (KYC) verification process.

However, Revolut has not disclosed the number of customers affected at the time of publication, pending ongoing investigations, as the company does not wish to divulge that information to avoid jeopardizing the probe.

According to data samples the threat actors shared, the stolen information affects high-profile individuals, including business executives, CEOs, sports professionals, and artists. Sources familiar with the matter claim that at least 680 individuals were contacted. ZachXBT, an independent cybersecurity sleuth, claims the data breach targeted high-net-worth individuals.

“While the incident is likely limited in size, it seems to have been targeted at high net worth users,” ZachXBT wrote.

At the moment, the hacked government department used to launch the attacks remains undisclosed. However, Revolut has notified relevant regulatory authorities, including the Office of the Data Protection Officer and financial regulators, to protect victims from fraud. The fintech firm has also notified a “limited” number of affected customers and blocked the government email domain used to make the fraudulent request for information.

Nevertheless, while Revolut claims a legitimate government email address was used, sharing personal information without proper legal warrants should raise eyebrows for a company of its magnitude.

So far, Revolut has no evidence that the data breach affected customer funds. It also remains unclear how the attacker gained access to a government email domain. However, phishing and social engineering attacks are the most common methods.

Meanwhile, the attackers are threatening to publish the stolen personal information unless Revolut pays a ransom of 10,000 bitcoin, equivalent to about $782 million. While the FBI discourages paying a ransom because doing so does not guarantee the recovery of stolen data, it also encourages organizations to consider the welfare of their investors, customers, and other affected individuals before refusing to pay. Nevertheless, Revolut has not indicated whether it plans to pay the ransom.

Financial services companies are prime targets for cybercriminals

As part of critical infrastructure, cybercriminals frequently target financial services companies to commit fraud and extort the victims.

In 2023, Cash App disclosed a 2021 data breach that stemmed from an insider threat that exposed the personal information of 8.2 million people.

In 2021, Robinhood experienced a similar data breach stemming from a social engineering attack that leaked the personal information of over 5 million people.

Other fintech-related companies affected by cybersecurity incidents include the Plaid data breach of 2021/2022 and the Experian 2021 hack that exposed 54 million people, the Capital One (2019) leak that affected 106 million individuals, and the Equifax 2017 hack that exposed 147 million customers.