Revolut's major fiasco: How a fake email "unlocked" the data of 680 clients – Fintechs prove dangerous

Revolut's major fiasco: How a fake email
Anti-impersonation, verification, and fraud detection systems failed to stop the hackers, insurance companies say

Hackers did not breach and steal the personal data of REVOLUT depositors and clients from within the fintech bank's systems in the conventional manner. REVOLUT itself approved its clients' personal data through its internal security system verification procedures. Insurance firms are launching new pricing for cyber risks as of today. REVOLUT was essentially the victim of its own undoing, and behind the fake email address hid hackers self-identifying as "Revolut Smilik."
They are now demanding ransom and threatening to leak sensitive personal data online. REVOLUT's security framework stands exposed as insecure; however, a critical question arises: if REVOLUT handed over information to a seemingly legitimate address, did it possess signed authorization from its clients, how informed are consumers, and under what conditions is personal data surrendered?

Approval and processing by REVOLUT and the opening for cybercrime

Revolut confirmed that it disclosed sensitive details belonging to approximately 680 customers after an impostor transmitted data requests from an email account using the domain of a legitimate online service. After passing the bank's technical authentication checks, these messages were approved and processed as routine, legally compliant requests. In other words, based on indicators within Revolut's systems, the messages originated from a verified source. Subsequently, a REVOLUT employee pressed the button and dispatched the records, creating a major cybercrime vulnerability.

What the data contained

The surrendered files reportedly encompassed dates of birth, residential and email addresses, phone numbers, copies of passports and driving licenses, identification photos, account statements, and transaction histories. Via the Telegraph, an entity allegedly issued a ransom threat, blackmailing that it would publish client personal information across the web. Notably, BN, through relevant coverage including a recent Greek report titled "Digital nightmare for businesses – AI a superweapon in the hands of hackers... cyberattacks reach another level" (translated title) dated 3/9/2026, has been striving to inform organizations regarding the threats posed by artificial intelligence. Insurance companies have begun repricing cyber risks. Underwriters have tightened and made more precise the policy terms covering social engineering risks, demanding that when payments are involved, the system must verify payment instructions directly from sender to recipient. Today, following the colossal blow suffered by REVOLUT, whose internal setup failed to detect the hackers, insurers are demanding that the payment verification framework be extended to non-monetary transactions as well.

Impersonation and fraud detection systems failed to distinguish the hackers

Revolut serves over 80 million customers and recently completed a share sale valuing the firm at $115 billion. Over the past 12 months, it secured new licenses and regulatory approvals across the UK, France, the US, and the UAE, while rolling out fraud detection tools and customer impersonation protections—including in-app call verification designed to block scammers posing as Revolut representatives. Despite these measures, the breach highlights persistent systemic vulnerabilities within fintech platforms.

El. Ermeidou
www.bankingnews.gr

Latest Stories

Readers’ Comments

Also Read