---
title: Data breach at Revolut caused by infection with infostealer malware
url: https://www.dataloco.com/en/data-breach-at-revolut-caused-by-infection-with-infostealer-malware
published: 2026-09-18T21:21:03+00:00
language: en
section: Security
source: https://www.security.nl/posting/953236/%27Datalek+bij+Revolut+veroorzaakt+door+infectie+met+infostealer-malware%27?channel=rss
publisher: Dataloco
---

# Data breach at Revolut caused by infection with infostealer malware

A data breach at Revolut, where an attacker gained access to the personal data of nearly seven hundred customers, is reportedly caused by an infection with infostealer malware. The Duel Investigations Team reported this via X. Revolut announced that it had received data requests from an unnamed governmental agency, originating from a legitimate email domain of this agency. Since the bank believed these were legitimate requests, the requested data was provided.

The data compromised in the attack includes names, birth dates, occupations, addresses, email addresses, phone numbers, copies of passports or driver’s licenses, and selfies provided for facial verification, as well as financial data, including transaction details and withdrawal summaries. Bitcoin-related data was also obtained. Among the victims of the data breach are over thirty individuals from the Netherlands.

The attacker claimed to have had access to systems of Italian authorities for months. Now, investigators report, based on contact with the attacker, that he gained access to the account of an Italian official through infostealer malware. Infostealer malware is specifically designed to steal login credentials, such as passwords and session cookies. How the infection occurred remains unknown.

From the hacked email account, the attacker sent requests to a Lithuanian branch of Revolut. The data requests contained hundreds of IDs of cryptocurrency transactions, based on data from public blockchains, researchers further revealed. The attacker then requested Revolut to provide the associated customer data, which the bank supplied.

Over a period of five months, the attacker sent numerous requests. In one instance, the attacker sent the wrong document. "Instead of realizing what was happening, the support department of Revolut explained what he needed to adjust," researchers stated. The claims made by the researchers have not been confirmed by Revolut.

## This story in other languages

- [Português (Brasil)](https://www.dataloco.com/pt-br/vazamento-de-dados-na-revolut-foi-causado-por-malware-de-roubo-de-informacoes)
