Revolut confirmed a data breach on September 12 2026 after a fraudster used a legitimate government‑email domain to request customer files, leading to an extortion site built on public hosting.
Revolut confirmed a data breach on September 12 2026 after a fraudster used a legitimate government‑email domain to request customer files, leading to an extortion site built on public hosting.
How the breach unfolded
The attacker posed as a government official, sending an email from a domain that closely resembled a real agency’s address. The message requested a batch of customer documents, which Revolut employees mistakenly supplied.
Once the files were obtained, the criminal set up an extortion site on a widely used cloud hosting provider. The site displayed stolen data and demanded payment for its removal, exploiting the public nature of the hosting service to evade immediate takedown.
Infrastructure of the extortion site
Technical analysis revealed that the site was hosted on a generic virtual private server (VPS) with no specialized security controls. The attacker leveraged default configurations, making it easy to spin up and shut down the site as needed.
- Domain registered through a privacy‑protected registrar
- Web server running a standard LAMP stack
- SSL certificate obtained via a free certificate authority
- No custom firewall rules or intrusion detection
Revolut’s response
Revolut promptly notified affected customers, revoked the compromised credentials, and engaged third‑party security firms to investigate. The company also began a review of its email verification processes to prevent similar social‑engineering attacks.
Customers were advised to monitor their accounts for suspicious activity, enable two‑factor authentication, and report any unauthorized transactions to Revolut’s support team.
“We are treating this incident with the utmost seriousness and are working closely with law enforcement to identify the perpetrators.”
The breach underscores the importance of verifying email origins, especially when requests involve sensitive data, and highlights how public hosting platforms can be abused for rapid extortion campaigns.
Comments
No comments yet.