2nd Revolut Breach in a Month, As Neobank Plans Dual Stock Listing
Revolut customers experienced a second breach in a month towards the end of September, as fraudsters social engineered their way into U.S. online brokerage DriveWealth and stole historic personally identifiable information (PII). Anyone who used Revolut to invest in U.S. stock up until December 2023 could be impacted.
DriveWealth provides execution and clearing services for investment firms and previously held brokerage accounts directly for Revolut customers trading US stocks. It said the unauthorized access occurred on September 4 and 5, according to a report in The Register.
Revolut confirmed that its own systems and infrastructure were not compromised during the breach, and that is customers’ funds and investments are safe. Neither Revolut nor DriveWealth could confirm how many Revolut customers were impacted.
The personal data compromised, according to Irish broadcast RTE, included names, email addresses, phone numbers, postal addresses, and employment information. Biographical data – such as country of citizenship, age, and gender – also may have been accessed. Nevertheless, DriveWealth downplayed the likelihood that passwords, credit card or bank details were among the exfiltrated information.
Reports of the second September data breach followed on the heels of media coverage of Revolut founder Nik Storonsky sharing plans to publicly list the neobank on both the London Stock Exchange and New York’s Nasdaq. Despite the negative press and security concerns raised by the two data breach, there has been no talk of a delay in Revolut’s initial public offering.
The initial Revolut breach in early September impacted roughly 680 customers, mostly based in Europe. A hacker group calling itself called “iamnotavillain” made a $3 million ransom demand, threatening to sell the stolen records. However, Revolut claimed they did not receive a demand directly from the group.
Customers accounts whose information was stolen by the hackers were allegedly targeted for their crypto holdings, according to a report by the Financial Times.
The hackers supposedly entrapped Revolut over the course of several months by impersonating Italian law enforcement after compromising an Italian government email system.
“This is very, very damaging [for the Revolut brand] because I do believe a lot of Revolut customers are more likely to be privacy sensitive,” said compromised Revolut customer and former chief executive of failed bitcoin exchange Mt. Gox, Mark Karpelès. He noted that privacy was usually a high priority among people invested in cryptocurrencies.
















