Revolut confirms customer data breach, falling for fake government requests
unbeli
40 points
6 comments
September 12, 2026
Related Discussions
Found 5 related stories in 61.4ms across 6,361 title embeddings via pgvector HNSW
- France's tax authority had data stolen on 680k taxpayers rzk · 53 pts · August 14, 2026 · 54% similar
- Hackers had a live feed of every ID verification company scanned for over a year beardyw · 539 pts · September 04, 2026 · 46% similar
- Dropbox Data Breach hmate9 · 24 pts · August 31, 2026 · 45% similar
- Trezor's email provider has been breached andreyazimov · 15 pts · September 09, 2026 · 45% similar
- Hacker wipes Romania's land registry database speckx · 620 pts · July 20, 2026 · 45% similar
Discussion Highlights (2 comments)
cluckindan
Revolut is a platform which enables money laundering, tax evasion, welfare fraud and sanctions workarounds. It needs to be cracked down on, not lauded as a unicorn or allowed to IPO.
Wicher
> sent from a legitimate government agency email domain, DMARC-verified-sent from a legitimate [...] domain? -> Someone pwned a mailbox at an agency? I'm sure they would've spun the story into "the government was hacked, not us" in that case. Or "sent from" a legitimate [...] domain? -> Spoofed envelope sender / FROM? Then Revolut's simply been had by the nose. If the domain is indeed a government domain, and does not publish DMARC records, then a due diligence check on who they're sending such personal info (ie, call that purported government agency up on the phone) would suit them. After all, they're very pedantic about me running their app on a phone with an unlocked bootloader. I'd then hope that they'd be symmetrically pedantic about verifying whoever they're sending my info to.