<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Fintech - PhishFort | AI-Powered Brand Protection</title><link>https://phishfort.com/resources/blog/tag/fintech/</link><description>PhishFort delivers agentic brand protection: detecting and eliminating phishing sites, fake apps, and impersonations across every digital channel.</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><lastBuildDate>Tue, 06 Oct 2026 07:35:51 +0000</lastBuildDate><atom:link href="https://phishfort.com/resources/blog/tag/fintech/index.xml" rel="self" type="application/rss+xml"/><item><title>DriveWealth Breach: What Revolut Users Need to Know</title><link>https://phishfort.com/revolut-drivewealth-third-party-breach/</link><pubDate>Tue, 06 Oct 2026 00:00:00 +0000</pubDate><dc:creator>PhishFort Team</dc:creator><guid>https://phishfort.com/revolut-drivewealth-third-party-breach/</guid><description><![CDATA[<p>In September 2026, Revolut notified customers that unauthorized parties had accessed historical personal data on systems belonging to DriveWealth, the US broker that runs Revolut&rsquo;s US stock trading. Revolut&rsquo;s own systems were not the source. The incident mainly affects customers who traded US stocks through Revolut before December 2023, and it shows that a fintech&rsquo;s exposure includes every partner that holds its customers&rsquo; data.</p>
<p><strong>Summary</strong></p>
<ul>
<li>DriveWealth, a US brokerage infrastructure provider and Revolut&rsquo;s stock trading partner, reported unauthorized access to historical personal data.</li>
<li>Revolut emailed potentially affected customers and confirmed that a separate email from DriveWealth LLC was genuine.</li>
<li>The affected data relates to customers who traded US stocks through Revolut before December 2023, which means some records were kept since 2022.</li>
<li>The case raises questions about cross-border jurisdiction and about data minimization under the EU General Data Protection Regulation (GDPR).</li>
<li>Breach notification emails are a common template for follow-up phishing, so customers should verify any security updates through the official app.</li>
</ul>
<h2 id="what-happened-in-the-drivewealth-security-incident">What happened in the DriveWealth security incident?</h2>
<p>DriveWealth confirmed unauthorized access to historical personal data stored on its systems, and Revolut notified customers who may be affected. The incident came weeks after Revolut handled a separate attack in which a fake government request led to the release of customer passports.</p>]]></description><content:encoded><![CDATA[<p>In September 2026, Revolut notified customers that unauthorized parties had accessed historical personal data on systems belonging to DriveWealth, the US broker that runs Revolut&rsquo;s US stock trading. Revolut&rsquo;s own systems were not the source. The incident mainly affects customers who traded US stocks through Revolut before December 2023, and it shows that a fintech&rsquo;s exposure includes every partner that holds its customers&rsquo; data.</p>
<p><strong>Summary</strong></p>
<ul>
<li>DriveWealth, a US brokerage infrastructure provider and Revolut&rsquo;s stock trading partner, reported unauthorized access to historical personal data.</li>
<li>Revolut emailed potentially affected customers and confirmed that a separate email from DriveWealth LLC was genuine.</li>
<li>The affected data relates to customers who traded US stocks through Revolut before December 2023, which means some records were kept since 2022.</li>
<li>The case raises questions about cross-border jurisdiction and about data minimization under the EU General Data Protection Regulation (GDPR).</li>
<li>Breach notification emails are a common template for follow-up phishing, so customers should verify any security updates through the official app.</li>
</ul>
<h2 id="what-happened-in-the-drivewealth-security-incident">What happened in the DriveWealth security incident?</h2>
<p>DriveWealth confirmed unauthorized access to historical personal data stored on its systems, and Revolut notified customers who may be affected. The incident came weeks after Revolut handled a separate attack in which a fake government request led to the release of customer passports.</p>
<p>PhishFort reviewed a notification Revolut sent to a potentially affected user. Titled &ldquo;DriveWealth security incident update&rdquo;, it states that unauthorized access to historical personal data occurred on DriveWealth&rsquo;s systems and that Revolut is working directly with DriveWealth to determine the scope.</p>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1791212015942-pasted-image_hu_de2c8df02076880a.webp 480w, /img/1791212015942-pasted-image_hu_14cd8288c5aa051c.webp 768w, /img/1791212015942-pasted-image_hu_c5ef6bd749c04629.webp 1200w, /img/1791212015942-pasted-image_hu_8ceca1d5d8aec617.webp 1600w, /img/1791212015942-pasted-image_hu_d5717046944656dc.webp 1690w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791212015942-pasted-image.png"
          srcset="/img/1791212015942-pasted-image_hu_692ee5ad9d7e2c1c.png 480w, /img/1791212015942-pasted-image_hu_edad47e89fba125c.png 768w, /img/1791212015942-pasted-image_hu_cd9b31899265bcc5.png 1200w, /img/1791212015942-pasted-image_hu_57b2a9298aa06832.png 1600w, /img/1791212015942-pasted-image.png 1690w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="1690" height="939"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<p>The notice tells the user they were identified as being potentially affected and adds: &ldquo;You recently received an email from DriveWealth LLC&hellip; That email is genuine and you should read it carefully alongside this one.&rdquo;</p>
<p>This is the DriveWealth email the notice refers to:</p>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1791212019267-pasted-image_hu_dfe39d90cc7b02e3.webp 480w, /img/1791212019267-pasted-image_hu_bb7efa8d45687310.webp 768w, /img/1791212019267-pasted-image_hu_6608c2c24a8ae3db.webp 1200w, /img/1791212019267-pasted-image_hu_87c4e05180012652.webp 1472w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791212019267-pasted-image.png"
          srcset="/img/1791212019267-pasted-image_hu_56bfe3f81722fde9.png 480w, /img/1791212019267-pasted-image_hu_28287edf11fa728.png 768w, /img/1791212019267-pasted-image_hu_112151973fa54a38.png 1200w, /img/1791212019267-pasted-image.png 1472w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="1472" height="1531"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<h2 id="who-is-affected-by-the-drivewealth-breach">Who is affected by the DriveWealth breach?</h2>
<p>The affected group is Revolut customers who traded US stocks before December 2023, according to the information shared with customers. Revolut has not published the total number of affected users. Customers who received both the Revolut and the DriveWealth emails should treat themselves as affected.</p>
<h2 id="how-did-revolut-and-drivewealth-communicate-the-incident">How did Revolut and DriveWealth communicate the incident?</h2>
<p>Both companies contacted affected customers directly by email. Revolut also placed a visible alert on its website and published a help page about the incident.</p>
<p>DriveWealth published a standalone cyber response page on a subdomain (<a href="http://legal.drivewealth.com" target="_blank" rel="noopener noreferrer nofollow">legal.drivewealth.com</a>). At the time of PhishFort&rsquo;s review, the page was not linked from DriveWealth&rsquo;s main navigation, which makes it harder for customers to confirm the notice is real.</p>
<h2 id="why-does-a-partners-breach-expose-a-fintechs-customers">Why does a partner&rsquo;s breach expose a fintech&rsquo;s customers?</h2>
<p>A fintech&rsquo;s customers are exposed wherever their data is stored, including at brokers, payment processors and identity verification vendors. A US broker that executes trades for a European digital bank holds names, addresses and account details of the bank&rsquo;s customers, so a breach at the broker reaches them directly.</p>
<p>This is a common pattern. The Verizon 2026 Data Breach Investigations Report (DBIR) found third-party involvement in 48% of breaches.</p>
<h2 id="what-are-the-jurisdiction-and-gdpr-questions">What are the jurisdiction and GDPR questions?</h2>
<p>The incident raises an open question about which rules apply: Lithuanian and EU law, where Revolut holds its European banking license, or US frameworks that govern DriveWealth. The answer affects notification deadlines, regulator involvement and customer remedies.</p>
<p>Retention is the second question. If records from as early as 2022 were still held, the case tests the GDPR principle of data minimization, which limits how long personal data can be kept. Financial institutions often cite legal and regulatory duties to retain records, but those duties do not cover every field indefinitely.</p>
<h2 id="how-do-attackers-exploit-breach-notification-emails">How do attackers exploit breach notification emails?</h2>
<p>Attackers copy real breach notices because customers expect them and act on them. After a public incident, fake &ldquo;security update&rdquo; emails, SMS messages and support accounts often reuse the real subject line, logo and wording, then point to a lookalike domain that asks for login details or identity documents.</p>
<p>Revolut&rsquo;s notice confirmed that the DriveWealth email was genuine, which helps. A copy of either message can still target a customer. Warning signs include:</p>
<ul>
<li>A link that asks you to log in, &ldquo;verify&rdquo; your identity or reset your account from the email itself.</li>
<li>A sender domain that is similar to, but not exactly, <a href="http://revolut.com" target="_blank" rel="noopener noreferrer nofollow">revolut.com</a> or <a href="http://drivewealth.com" target="_blank" rel="noopener noreferrer nofollow">drivewealth.com</a>.</li>
<li>Requests for passwords, one-time codes, card details or ID photos.</li>
<li>Unsolicited calls or chat messages that reference the incident.</li>
</ul>
<p>Customers should open the Revolut app directly to check any security notice.</p>
<h2 id="what-should-fintechs-do-about-third-party-risk">What should fintechs do about third-party risk?</h2>
<p>Fintechs can reduce partner risk by limiting what partners hold and planning the customer response before an incident. Practical steps:</p>
<ol>
<li>Map which partners store customer data, which fields and for how long.</li>
<li>Set contractual retention limits and deletion obligations that match GDPR data minimization.</li>
<li>Agree breach notification timelines and a joint communication plan with each partner.</li>
<li>Publish incident pages on the main domain and link them from the homepage, so customers can verify notices.</li>
<li>Monitor for lookalike domains and fake support accounts that use the incident as a lure.</li>
</ol>
<h2 id="how-phishfort-helps-after-a-third-party-incident">How PhishFort helps after a third-party incident</h2>
<p>When a partner is breached, attackers impersonate both brands. <a href="https://phishfort.com/product/brand-protection/" target="_blank" rel="noopener"><u>PhishFort Brand Protection</u></a> detects lookalike domains, fake support accounts and fake apps that use the incident as a lure, and takes them down with registrars, hosts and platforms.</p>
<h2 id="frequently-asked-questions">Frequently asked questions</h2>
<h3 id="was-revolut-hacked-in-the-drivewealth-incident">Was Revolut hacked in the DriveWealth incident?</h3>
<p>No. The unauthorized access happened on the systems of DriveWealth, Revolut&rsquo;s US stock trading partner. Revolut notified potentially affected customers and said it is working with DriveWealth to determine the scope.</p>
<h3 id="who-is-affected-by-the-drivewealth-breach-1">Who is affected by the DriveWealth breach?</h3>
<p>According to information shared with customers, the incident affects Revolut users who traded US stocks before December 2023. Revolut has not published the total number of affected users.</p>
<h3 id="is-the-drivewealth-breach-email-real">Is the DriveWealth breach email real?</h3>
<p>Revolut told customers that the email from DriveWealth LLC is genuine. Copies of breach notices are a common phishing lure, so check any security notice inside the Revolut app rather than through email links.</p>
<h3 id="what-is-third-party-risk-in-fintech">What is third-party risk in fintech?</h3>
<p>Third-party risk is the exposure a fintech takes on when partners such as brokers, processors or verification vendors store or process its customers&rsquo; data. A breach at the partner affects the fintech&rsquo;s customers even if the fintech&rsquo;s own systems are secure.</p>
<h2 id="sources">Sources</h2>
<ul>
<li><a href="https://legal.drivewealth.com/cyber-response" target="_blank" rel="noopener noreferrer nofollow">DriveWealth cyber response page</a></li>
<li><a href="https://help.revolut.com/en-US/help/security-logging-in/drivewealth-security-incident/question-drivewealth-data-incident/" target="_blank" rel="noopener noreferrer nofollow">Revolut Help Center: DriveWealth data incident</a></li>
<li>Revolut customer notification &ldquo;DriveWealth security incident update&rdquo;, reviewed by PhishFort, September 2026.</li>
<li>Verizon 2026 Data Breach Investigations Report (DBIR).</li>
</ul>
]]></content:encoded><category>Financial Services</category><category>phishing</category><category>security</category><category>DriveWealth</category><category>Revolut</category><category>third-party risk</category><category>supply chain security</category><category>data breach</category><category>GDPR</category><category>fintech</category><category>breach notification phishing</category></item><item><title>Revolut Data Leak: Fake Government Request Passed DMARC</title><link>https://phishfort.com/revolut-fake-government-data-request-dmarc/</link><pubDate>Mon, 05 Oct 2026 13:59:13 +0000</pubDate><dc:creator>PhishFort Team</dc:creator><guid>https://phishfort.com/revolut-fake-government-data-request-dmarc/</guid><description>&lt;p>In September 2026, Revolut released customer passports, verification selfies, account statements and full Bitcoin transaction histories to an attacker who sent fraudulent information requests from an unauthorized account on a real government agency email domain. The emails passed SPF, DKIM and DMARC, so they looked authentic. The lesson for every financial institution: email authentication proves which domain sent a message, not that the person behind it is allowed to ask for customer data.&lt;/p></description><content:encoded><![CDATA[<p>In September 2026, Revolut released customer passports, verification selfies, account statements and full Bitcoin transaction histories to an attacker who sent fraudulent information requests from an unauthorized account on a real government agency email domain. The emails passed SPF, DKIM and DMARC, so they looked authentic. The lesson for every financial institution: email authentication proves which domain sent a message, not that the person behind it is allowed to ask for customer data.</p>
<p><strong>Summary</strong></p>
<ul>
<li>Revolut fulfilled fraudulent data requests that came from an unauthorized email account created inside a legitimate government agency domain.</li>
<li>The requests passed SPF, DKIM and DMARC checks, the standard email authentication controls used to block spoofed email.</li>
<li>Exposed data included identity documents, onboarding selfies, IBANs, wallet references and full transaction histories, including Bitcoin activity. Passwords, private keys and full card details were not shared.</li>
<li>Revolut said systems and customer funds were not affected and notified a limited number of customers, regulators and law enforcement.</li>
<li>The attack targeted a process (how data requests are verified), not a system. Out-of-band verification is the control that would have stopped it.</li>
</ul>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1791208470734-pasted-image_hu_8ec9903b9f2e815d.webp 480w, /img/1791208470734-pasted-image_hu_d28fdd2f36c1c66c.webp 768w, /img/1791208470734-pasted-image_hu_37d8d1dbad086bd5.webp 1200w, /img/1791208470734-pasted-image_hu_ce7d82c99fe3a997.webp 1600w, /img/1791208470734-pasted-image_hu_99936d179bfa9432.webp 1920w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791208470734-pasted-image.png"
          srcset="/img/1791208470734-pasted-image_hu_522d9c5ea126b1ed.png 480w, /img/1791208470734-pasted-image_hu_6a3916f7f70212cb.png 768w, /img/1791208470734-pasted-image_hu_8e3064fb8e2bf088.png 1200w, /img/1791208470734-pasted-image_hu_8b60a297e1b34a4e.png 1600w, /img/1791208470734-pasted-image.png 1920w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="1920" height="1080"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<h2 id="what-happened-in-the-revolut-data-disclosure-incident">What happened in the Revolut data disclosure incident?</h2>
<p>Revolut treated a fraudulent information request as a genuine request from a government agency and sent sensitive customer data in response. The request came from an unauthorized email account created within the agency&rsquo;s real domain infrastructure, carried valid domain authentication and passed SPF, DKIM and DMARC.</p>
<p>Customer notices began circulating on September 11, 2026. Blockchain investigator ZachXBT and former Mt. Gox CEO Mark Karpelès helped bring the notices into public view, and crypto media covered the story on September 12. Revolut later confirmed the incident to media outlets.</p>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
      
        
      
        
      
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1791208474359-pasted-image_hu_f4d3fd57fa664650.webp 447w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791208474359-pasted-image.png"
          srcset="/img/1791208474359-pasted-image.png 447w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="447" height="603"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
      
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1791208476818-pasted-image_hu_8b0b11b00dca977.webp 480w, /img/1791208476818-pasted-image_hu_e21b56694a1e15b6.webp 768w, /img/1791208476818-pasted-image_hu_1765a1fd15111246.webp 1092w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791208476818-pasted-image.png"
          srcset="/img/1791208476818-pasted-image_hu_65e3a298b9a1243e.png 480w, /img/1791208476818-pasted-image_hu_c8b6c0491acbd14c.png 768w, /img/1791208476818-pasted-image.png 1092w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="1092" height="584"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<p>A Revolut spokesperson described it as &ldquo;a sophisticated external impersonation attack where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.&rdquo; After detection, Revolut blocked the sender and alerted the agency, law enforcement, data protection authorities and financial regulators.</p>
<p>Revolut has not disclosed how many customers were affected or which agency&rsquo;s domain was abused, citing an ongoing police investigation. On-chain researchers said the affected group appears small and skewed toward higher net worth individuals.</p>
<h2 id="what-customer-data-did-revolut-share">What customer data did Revolut share?</h2>
<p>According to the customer notices, the disclosure package included:</p>
<ul>
<li>Full names, dates of birth, occupations, postal addresses, email addresses and phone numbers.</li>
<li>Copies of identity documents (passports or driver&rsquo;s licenses).</li>
<li>Verification selfies submitted during onboarding.</li>
<li>Account statements with IBANs, account status, opening dates and wallet reference numbers.</li>
<li>Withdrawal records and complete transaction histories, including Bitcoin activity.</li>
</ul>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
      
        
      
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1791208479139-pasted-image_hu_fe362c0ed0f12b6f.webp 480w, /img/1791208479139-pasted-image_hu_1fd24432fa635bca.webp 577w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791208479139-pasted-image.png"
          srcset="/img/1791208479139-pasted-image_hu_13a56f2e2e1b3d9.png 480w, /img/1791208479139-pasted-image.png 577w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="577" height="759"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<p>Revolut said the derived biometric face template was not shared, only the original selfie image. Login credentials, passwords, private keys and full payment card details were not part of the disclosure.</p>
<h2 id="why-did-the-fake-request-pass-spf-dkim-and-dmarc">Why did the fake request pass SPF, DKIM and DMARC?</h2>
<p>The fake request passed authentication because it was sent from the real government domain. SPF, DKIM and DMARC check whether an email truly comes from the domain it claims. They do not check whether the individual account sending it is authorized to request data.</p>
<p>The three controls answer different questions:</p>
<table style="min-width: 75px;"><tbody><tr><td colspan="1" rowspan="1"><strong>Control</strong></td><td colspan="1" rowspan="1"><strong>What it verifies</strong></td><td colspan="1" rowspan="1"><strong>What it does not verify</strong></td></tr><tr><td colspan="1" rowspan="1">SPF (Sender Policy Framework)</td><td colspan="1" rowspan="1">The sending server is allowed to send email for the domain</td><td colspan="1" rowspan="1">Who wrote the email or why</td></tr><tr><td colspan="1" rowspan="1">DKIM (DomainKeys Identified Mail)</td><td colspan="1" rowspan="1">The message was signed by the domain and not altered in transit</td><td colspan="1" rowspan="1">Whether the signing account was created or used legitimately</td></tr><tr><td colspan="1" rowspan="1">DMARC (Domain-based Message Authentication, Reporting and Conformance)</td><td colspan="1" rowspan="1">SPF or DKIM aligns with the visible From domain, and what to do if not</td><td colspan="1" rowspan="1">Whether the request is authorized or the sender is who they claim to be</td></tr></tbody></table>
<p>An attacker with an account inside a trusted domain, whether created without authorization or taken over, inherits that domain&rsquo;s reputation. Every check passes, and the message lands as trusted mail.</p>
<h2 id="what-is-the-difference-between-dmarc-and-brand-protection">What is the difference between DMARC and brand protection?</h2>
<p>DMARC protects your own email domain from being spoofed in email. Brand protection covers the impersonation that happens outside your infrastructure: lookalike domains, fake websites, fake apps, fake social media profiles and fake support channels that use your name.</p>
<p>The Revolut case shows the limit of both when used alone. DMARC worked as designed, and the attacker still succeeded because the trusted identity was abused from the inside. Brand protection matters after the incident, when attackers use the news to send follow-up phishing that impersonates the affected company or the agency involved.</p>
<h2 id="how-can-financial-institutions-verify-government-and-law-enforcement-data-requests">How can financial institutions verify government and law enforcement data requests?</h2>
<p>Financial institutions can stop this attack pattern by verifying every high-sensitivity data request through a channel the requester did not provide. Practical steps, in order of priority:</p>
<ol>
<li>Confirm each request out of band, using a contact number or portal you sourced independently, never the details in the email.</li>
<li>Keep a registry of known agency contacts and request formats, and flag any request from an address that is not on it, even inside a valid domain.</li>
<li>Require two-person review for any disclosure that includes identity documents, biometric images or full transaction histories.</li>
<li>Apply data minimization: share only the fields the legal basis requires, not the full customer file.</li>
<li>Log every disclosure and alert on unusual volume, unusual targets (for example, high net worth accounts) or unusual timing.</li>
<li>Train compliance and legal teams to treat urgency and authority in a request as risk signals, not reasons to skip checks.</li>
</ol>
<h2 id="why-does-this-matter-for-crypto-users">Why does this matter for crypto users?</h2>
<p>Pairing a passport image and home address with a full Bitcoin transaction history links a real-world identity to on-chain activity. For customers who buy, sell or withdraw crypto through Revolut or its Revolut X exchange, that link raises the risk of targeted phishing, extortion and physical threats against self-custody holders.</p>
<p>Crypto users are already a frequent phishing target. In PhishFort&rsquo;s Digital Threat Intelligence Report for January to June 2026, Crypto and DeFi accounted for 14.4% of confirmed brand impersonation cases and Financial Services and Banking for 18.6% (PhishFort internal data).</p>
<h2 id="what-should-affected-revolut-customers-watch-for">What should affected Revolut customers watch for?</h2>
<p>Affected customers should expect follow-up phishing that uses their real details to look credible. Warning signs include:</p>
<ul>
<li>Messages that reference your passport, address or transaction history and ask you to &ldquo;verify&rdquo; or &ldquo;secure&rdquo; your account.</li>
<li>Unsolicited contact from &ldquo;Revolut support&rdquo;, a regulator or a government agency, by email, SMS, phone, Telegram or WhatsApp.</li>
<li>Requests to move funds to a &ldquo;safe&rdquo; wallet or to share recovery phrases or one-time codes.</li>
<li>Links to domains that look similar to <a href="http://revolut.com" target="_blank" rel="noopener noreferrer nofollow">revolut.com</a> but are not the official domain.</li>
</ul>
<p>Contact Revolut only through the official app, and treat any unexpected request for more data as suspicious, even when it knows your details.</p>
<h2 id="how-phishfort-helps-after-an-impersonation-incident">How PhishFort helps after an impersonation incident</h2>
<p>After incidents like this, attackers register lookalike domains and open fake support accounts to reach worried customers. <a href="https://phishfort.com/product/brand-protection/" target="_blank" rel="noopener noreferrer nofollow"><u>PhishFort Brand Protection</u></a> monitors new domain registrations, social media and app stores for impersonation of your brand and handles the takedown with registrars, hosting providers and platforms.</p>
<h2 id="frequently-asked-questions">Frequently asked questions</h2>
<h3 id="did-hackers-breach-revoluts-systems">Did hackers breach Revolut&rsquo;s systems?</h3>
<p>No. Revolut said its systems and customer funds were not affected. The attacker used social engineering: a fraudulent request from a real government email domain convinced Revolut to send customer data voluntarily.</p>
<h3 id="does-dmarc-stop-impersonation-attacks">Does DMARC stop impersonation attacks?</h3>
<p>DMARC stops attackers from spoofing your exact domain in email, but it does not stop attacks sent from a legitimate domain the attacker controls or has access to. In the Revolut case, the request passed SPF, DKIM and DMARC because it came from a real government domain.</p>
<h3 id="what-data-was-exposed-in-the-revolut-incident">What data was exposed in the Revolut incident?</h3>
<p>According to customer notices, the data included names, contact details, passport or driver&rsquo;s license copies, onboarding selfies, IBANs, wallet references and full transaction histories including Bitcoin activity. Passwords, private keys and full card details were not shared.</p>
<h3 id="how-should-banks-verify-law-enforcement-data-requests">How should banks verify law enforcement data requests?</h3>
<p>Banks should confirm every sensitive request through an independently sourced contact at the requesting agency, keep a registry of known agency contacts, require two-person review for identity data and share only the minimum data required.</p>
<h2 id="sources">Sources</h2>
<ul>
<li>Revolut statement to media on the impersonation attack, September 2026.</li>
<li>Customer notices shared publicly by ZachXBT and Mark Karpelès, September 11, 2026.</li>
<li>PhishFort Digital Threat Intelligence Report, January to June 2026 (PhishFort internal data).</li>
</ul>
]]></content:encoded><category>Financial Services</category><category>phishing</category><category>security</category><category>Revolut</category><category>impersonation</category><category>DMARC</category><category>email authentication</category><category>KYC data</category><category>social engineering</category><category>fintech</category><category>crypto</category></item></channel></rss>