// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
Breach Record

Revolut

DISCLOSED 2026-09-22 · PHISHING

Fintech company Revolut disclosed a data breach after sharing customer data with a threat actor impersonating a government agency. The exposed data includes financial information and passports. The number of affected customers was not disclosed.

The record

What we know

Disclosed
2026-09-22
Attack vector
Phishing
Sector
fintech
Data classes exposed
financial infopassports
ColdRecon assessment

Could a positive-security control have prevented this?

Verdict · unclear · opinion

The attack involved social engineering to impersonate a government agency, likely targeting employees or processes rather than endpoint changes. A positive-security model focused on endpoint state would not directly address this vector.

Our assessments are opinion, grounded in the cited public facts. Read them critically.

Sources

Cited reporting

Similar vector · recent

Other phishing breaches on file

This page is the permanent ColdRecon entry for the Revolut disclosure. It updates if new public reporting emerges. All tracked breaches →

Revolut just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →