S&P Global Targets $10B Blockchain Lending Market With New Risk Tool
S&P’s Vault Risk Assessment weighs six risks in DeFi lending as vault deposits reach $10 billion, but it is not a credit…
The institution shared personally identifiable information from an unknown number of users after receiving a request from an unauthorized government email account. The shared documents include identity details, ID and…
Published:Sep 12, 2026, 11:14 AM EDTRevolut Leaks Customer Data to Hackers Posing as State Agency
The institution shared personally identifiable information from an unknown number of users after receiving a request from an unauthorized government email account. The shared documents include identity details, ID and verification information, and financial statements, putting affected users at risk.
WRITTEN BY
Sergio GoschenkoSHAREPublished: Sep 12, 2026, 11:14 AM EDT
Revolut, a UK-based neobank, became the latest institution to inadvertently disclose client information to threat actors.
According to an email sent to customers, Revolut, which has a user base of over 70 million customers globally, shared personally identifiable information (PII) with unidentified threat actors who posed as a government agency. The company reported that it delivered this data while it was complying with a request-for-information email that originated from an unauthorized address hosted on a domain.
“The communication carried genuine domain authentication credentials leading Revolut to fulfill the request under the reasonable belief that it was an authentic government agency request,” it stressed.
Revolut did not disclose the name of the institution allegedly involved. Nonetheless, it did point out that the shared information included key details: names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers, potentially risking the personal security of the customers involved in the leak.
In addition, Revolut also shared documents and verification data, including passport and driver’s licence images with facial verification pictures, which can expose them to ID theft.
Marc Zeller, founder of the now-defunct Aave Chan Initiative, was one of the customers affected by the leak.
“Woke up to all my data leaked by Revolut. Sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way,” he posted on social media channels.
Onchain sleuth ZachXBT pointed out that while the incident was likely limited in size, it seems to have been aimed at high-net-worth users, increasing the chances of being targeted for affected customers.
The incident comes amid a global know-your-customer (KYC) backlash after several institutions and crypto companies have also leaked client information to threat actors, risking users’ personal security, as wrench attacks have risen in frequency and ferocity.
This week, the crypto community is discussing how cybersecurity experts from Krebs on Security’s researcher and journalist Brian Krebs, have…
This week, the crypto community is discussing how cybersecurity experts from Krebs on Security’s researcher and journalist Brian Krebs, have…
Read Now
This week, the crypto community is discussing how cybersecurity experts from Krebs on Security’s researcher and journalist Brian Krebs, have…
Tags in this storyBankSecurity
S&P’s Vault Risk Assessment weighs six risks in DeFi lending as vault deposits reach $10 billion, but it is not a credit…
S&P’s Vault Risk Assessment weighs six risks in DeFi lending as vault deposits reach $10 billion, but it is not a credit…
The stock trading platform seeks to offer tokenized shares in more than 60 US-listed companies under the SEC’s recently introduced innovation exemption.
Tokenized stocks market supply is at $3.2B and projected to hit $2T by 2028-2030.
The institution shared personally identifiable information from an unknown number of users after receiving a request from an unauthorized government email account. The shared documents include identity details, ID and…
Published:Sep 12, 2026, 11:14 AM EDTRevolut Leaks Customer Data to Hackers Posing as State Agency
The institution shared personally identifiable information from an unknown number of users after receiving a request from an unauthorized government email account. The shared documents include identity details, ID and verification information, and financial statements, putting affected users at risk.
WRITTEN BY
Sergio GoschenkoSHAREPublished: Sep 12, 2026, 11:14 AM EDT
Revolut, a UK-based neobank, became the latest institution to inadvertently disclose client information to threat actors.
According to an email sent to customers, Revolut, which has a user base of over 70 million customers globally, shared personally identifiable information (PII) with unidentified threat actors who posed as a government agency. The company reported that it delivered this data while it was complying with a request-for-information email that originated from an unauthorized address hosted on a domain.
“The communication carried genuine domain authentication credentials leading Revolut to fulfill the request under the reasonable belief that it was an authentic government agency request,” it stressed.
Revolut did not disclose the name of the institution allegedly involved. Nonetheless, it did point out that the shared information included key details: names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers, potentially risking the personal security of the customers involved in the leak.
In addition, Revolut also shared documents and verification data, including passport and driver’s licence images with facial verification pictures, which can expose them to ID theft.
Marc Zeller, founder of the now-defunct Aave Chan Initiative, was one of the customers affected by the leak.
“Woke up to all my data leaked by Revolut. Sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way,” he posted on social media channels.
Onchain sleuth ZachXBT pointed out that while the incident was likely limited in size, it seems to have been aimed at high-net-worth users, increasing the chances of being targeted for affected customers.
The incident comes amid a global know-your-customer (KYC) backlash after several institutions and crypto companies have also leaked client information to threat actors, risking users’ personal security, as wrench attacks have risen in frequency and ferocity.
This week, the crypto community is discussing how cybersecurity experts from Krebs on Security’s researcher and journalist Brian Krebs, have…
This week, the crypto community is discussing how cybersecurity experts from Krebs on Security’s researcher and journalist Brian Krebs, have…
Read Now
This week, the crypto community is discussing how cybersecurity experts from Krebs on Security’s researcher and journalist Brian Krebs, have…
Tags in this storyBankSecurity
S&P’s Vault Risk Assessment weighs six risks in DeFi lending as vault deposits reach $10 billion, but it is not a credit…
S&P’s Vault Risk Assessment weighs six risks in DeFi lending as vault deposits reach $10 billion, but it is not a credit…
The stock trading platform seeks to offer tokenized shares in more than 60 US-listed companies under the SEC’s recently introduced innovation exemption.
Tokenized stocks market supply is at $3.2B and projected to hit $2T by 2028-2030.