• Revolut sent identity data, contact details, and documents to hac

    From TechnologyDaily@1337:1/100 to All on Mon Sep 14 16:00:20 2026
    Revolut sent identity data, contact details, and documents to hackers posing as a government agency

    Date:
    Mon, 14 Sep 2026 14:40:00 +0000

    Description:
    Revolut is now being asked to pay a humongous ransom demand to keep the data private.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Revolut fell for a spoofed government email scam, leaking sensitive customer data to attackers Compromised info includes IDs, selfies, account statements, IBANs, and full transaction histories Criminals now allegedly leaking data on Telegram, demanding 10,000 BTC (~$780M) ransom from Revolut Digital banking platform Revolut was tricked into giving away a treasure trove of sensitive customer data to hackers, and it is now coming back to bite it.

    The company told TechCrunch that it recently fell victim to a sophisticated external impersonation scam in which the threat actor utilized a legitimate government agency domain email to submit fraudulent requests for information. In other words, the attackers either broke into, or spoofed, an email address belonging to the police, tax authorities, or other government bodies with statutory powers to demand information, and used them to demand Revolut hand over sensitive customer data . Latest Videos From TechRadar Watch full video here: Demanding ransom Cybernews reports that the compromised data includes customers birth dates, postal and email addresses, occupation, phone numbers, and copies of identity documents. TechCrunch added that verification selfies, account statements, and transaction histories may have also been compromised, together with IBANs, withdrawal records, complete transaction histories, and Bitcoin transactions.

    Should these reports be confirmed, this will be a bonafide fiasco for
    Revolut. You may like US Treasury wants banks to be better at filing file cyber scam reports after noting nearly $13 billion in losses since 2023 Manchester Airports hack: Experts weigh in on 8.7M data leak Top US hedge funds targeted by major vishing campaign

    "Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators," a company spokesperson told Reuters over the weekend.

    So far, we dont know exactly how many people are affected. Revolut said it is a very limited number, and that all of them had been notified already. Are
    you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro
    newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    According to Coin Bureau , the criminals have started leaking sensitive data on Telegram, in a bid to pressure Revolut into paying a ransom demand. The publication shared screenshots of the threat actors apparently leaking a selfie and full KYC of a CEO of a crypto casino website, saying that the crooks are now demanding 10,000 BTC in exchange for deleting the data.

    This would put the ransom demand at approximately $780 million which is obscene even by criminal standards.

    "This one is deeply concerning and the implications for affected customers go well beyond a standard data breach notification," said Muhammad Yahya Patel, vCISO & Cybersecurity Advisor at Huntress. "Passports, driver's licenses, verification selfies, account statements, transaction histories, birth dates, addresses that's not a data leak, that's a complete identity theft kit handed to whoever sent those fraudulent requests." What to read next ShinyHunters hackers claim to have hit data center provider used by Microsoft and Meta Millions of stolen records allegedly dumped online by mystery "Hatman" hacker
    McDonalds, Vodafone and more see Microsoft Azure records stolen Ransomware hackers dump 1.4 million stolen records from German government

    "Every single component needed to impersonate someone, open accounts in their name, or bypass checks at other financial institutions is in that package. On the dark web, that kind of profile doesn't sell as individual records it
    sells as a ready-made fraud pack, and it commands a significant premium precisely because of its completeness."

    "For a fintech built on digital identity verification, the bar for verifying third-party data requests should be exceptionally high. The question isn't
    why an attacker tried this. It's why a regulated financial institution handling highly sensitive data didn't have sufficiently rigorous verification controls to catch it," Patel concluded.

    Via Cybernews The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/revolut-sent-identity-data-contact-deta ils-and-documents-to-hackers-posing-as-a-government-agency


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)