Global English
Technology

Experts Warn Critical Lessons Must Be Learned Following Sophisticated Cyber Attack on Revolut

The NationalSeptember 21, 2026 at 06:07 PM1 views
Experts Warn Critical Lessons Must Be Learned Following Sophisticated Cyber Attack on Revolut

Disclaimer

This story, titled "Lessons must be learnt from cyber attack on Revolut, experts warn" First published on The National and was retrieved from its original source on September 21, 2026.

Our site bears no responsibility for its content. You can review the details of this story at its original source.

Cybersecurity experts are warning that significant lessons must be learned after digital banking platform Revolut fell victim to a deceptive scheme that handed private customer data over to hackers. The UK-based financial technology firm, which serves more than 80 million customers, confirmed that an individual posing as an Italian government regulator via email successfully acquired identification card information, photos, account statements, transaction histories, and other sensitive data.

Reports suggest that the hackers are already leaking the stolen information and demanding a ransom from Revolut to prevent further data exposure. Revolut has not yet responded to requests for comment. Technology experts and cybersecurity analysts note that this specific method of attack is likely to grow in popularity among criminal groups.

“Nobody broke into Revolut's systems, the attackers asked for the data and the bank sent it,” said Ivan Milenkovic, vice president for cyber risk technology at IT security firm Qualys. Mr. Milenkovic explained that while the criminals hacked an Italian government email system to impersonate law enforcement, they also exploited human nature. “The weak point was the desk that answers police requests and how much it trusts a government domain,” he said, adding that the stolen information—including passports, driving licences, and verification selfies—was particularly worrisome. “You can reset a password in a minute but you can't reset your face.”

Santiago, a threat-intelligence research lead at Acronis, reflected on how what initially seemed to be a data breach quickly turned into extortion, with hackers reportedly demanding roughly $3 million in blockchain-based cryptocurrency. Although Revolut stated it received no direct demand, the public countdown heightened pressure on the bank and affected customers. This type of phishing, he noted, has long been incorrectly dismissed as something only older or less technical people fall for. “Evidence demonstrates this stereotype is outdated and anyone can be deceived when an approach fits the context and arrives through a channel they already trust,” Mr. Pontiroli said, emphasizing that the targets were employees handling official requests rather than inexperienced consumers.

Art Gilliland, chief executive of Delinea, argued that it is counterproductive to reduce such attacks to a question of technical literacy. “The request carried strong signals of legitimacy and authority that many experienced professionals could reasonably find convincing,” he said. Because reports indicate about 650 Revolut customers were affected, Mr. Gilliland believes the goal was not necessarily to collect mass data, but to pinpoint individuals whose information provided maximum leverage. He stressed that even the most seasoned experts and organizations must learn from the incident. “Organisations cannot make employees, no matter how tech savvy they may be, the final line of defence,” he stated.

Revolut is not alone in facing such tactics. Technology, culture, and philosophy writer Joan Westenberg recently detailed a social engineering attempt disguised as a podcast invitation. She noted that the prep work was remarkably thorough before the individuals sent a link requesting a terminal command installation, prompting her to halt communication. Mr. Pontiroli identified this as an instance of “ClickFix-style social engineering,” which is increasingly favored by state-sponsored hackers in North Korea. He added that while the tactics are not new, the rise of artificial intelligence has made them significantly cheaper, faster, and easier to scale.

Share this article: