Home Cybersecurity InsightsRevolut Faces Second Data Breach in September

Revolut Faces Second Data Breach in September

by Sienna Marques
1 views 1 minutes read
Revolut Faces Second Data Breach in September

Customers of Revolut have experienced a second data breach this month, as attackers accessed historical personal information stored by US brokerage DriveWealth. This security incident occurred due to a social engineering attack on DriveWealth, which offers execution and clearing services to investment firms. Previously, the company directly managed brokerage accounts for Revolut customers and reported unauthorized access on September 4 and 5.

DriveWealth described the breach as resulting from a "complex social engineering scheme." Intruders accessed the personal details of clients who previously held accounts with the firm. The compromised data may include clients' names, email addresses, phone numbers, home addresses, employment status, age, and gender.

In its assessment, DriveWealth suggested that no sensitive information, such as passwords, transaction data, or bank credentials, had been disclosed. Revolut confirmed that some of its clients had indeed been impacted, with records obtained from their prior partnership with DriveWealth. Both companies have notified customers affected by the breach but have not revealed the number of Revolut users involved.

This incident follows another breach disclosed by Revolut on September 12, where criminals gained unauthorized access to sensitive customer information by impersonating a legitimate government agency through fraudulent requests. While the two breaches involved different attackers and tactics, the personal information stolen in the DriveWealth incident could still be exploited for phishing, forgery, or further social engineering attempts.

You may also like