Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Revolut

Revolut Vendor Cyber Rating & Cyber Score

revolut.com

People deserve more from their money. More visibility, more control, and more freedom. Since 2015, Revolut has been on a mission to deliver just that. Our powerhouse of products help our 70+ million customers get more from their money every day. As we continue our lightning-fast growth,‌ 2 things are essential to our success: our people and our culture. In recognition of our outstanding employee experience, we've been certified as a Great Place to Work™. So far, we have 10,000+ people working around the world, from our offices and remotely, to help us achieve our mission. And we're looking for more brilliant people. People who love building great products, redefining success, and turning the complexity of a chaotic world into the


Revolut A.I CyberSecurity Scoring

Revolut
Company Information
Website:https://www.revolut.com
Employees number:19,786
Number of followers:2,138,749
NAICS:52
Industry Type:Financial Services
Homepage:revolut.com
Revolut Risk Score (AI oriented)
Between 0 and 549
logo
RevolutFinancial Services
Updated:
17/09/2026
328/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Revolut Global Score (TPRM)
xxxx
logo
RevolutFinancial Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

RevolutCritical
Current Score
328C (CRITICAL)
01000
12 incidents
-72 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
376Before Incident
Breach
16 Sep 2026Revolut
Revolut: Revolut says no direct demand received over alleged data breach

Revolut Alleged Data Breach

328After Incident
CRITICAL-48
REV1789598285
Revolut Denies Receiving Direct Ransom Demand Amid Alleged Data Breach Revolut, the global fintech firm, has stated it has not received a direct ransom demand following reports of an alleged data breach. The incident surfaced after cybercriminals claimed to have accessed sensitive customer information, though the company has not confirmed the extent of any potential exposure. Details remain limited, but the breach appears linked to a third-party vendor, raising concerns about supply chain vulnerabilities in financial services. While Revolut has not disclosed specific timelines or affected regions, the incident underscores growing risks in digital banking security. The company is reportedly investigating the claims, though no official regulatory filings or public disclosures have been made as of yet. The potential breach highlights the increasing sophistication of cyber threats targeting fintech platforms and their partners.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Sensitive customer information
DATA BREACH
Type Of Data Compromised: Sensitive customer informationSensitivity Of Data: High
SEPTEMBER 2026
428Before Incident
Breach
15 Sep 2026Revolut
Revolut: Hackers demand Revolut hand over $3m ransom amid data breach

Revolut Faces Extortion Threat After Data Breach Affecting 680 Customers

328After Incident
CRITICAL-100
REV1789641174
Revolut Faces Extortion Threat After Data Breach Affecting 680 Customers A hacking group calling itself iamnotavillain has publicly demanded a $3 million ransom from Revolut, threatening to sell the stolen data of approximately 680 customers if the digital bank fails to pay within 24 hours. The ultimatum, posted on the group’s website alongside a countdown timer, marks an unusual departure from typical ransomware tactics, which usually involve private negotiations before escalating to public leaks. The hackers, who communicated with the Financial Times via Telegram, provided redacted screenshots and a 60-second video allegedly showing compromised customer data, including passports, driving licenses, identity verification images, and transaction histories. The breach appears to have targeted accounts with significant cryptocurrency holdings, identified through blockchain analysis. According to reports, the attackers gained access by compromising an Italian government email system, impersonating law enforcement to request customer data from Revolut over several months. Revolut stated it had not received direct contact from the group but confirmed it was assisting affected customers and collaborating with authorities. The fintech giant, valued at $115 billion and serving 80 million customers across 30+ countries, has not disclosed further details on the breach’s scope or response. The incident underscores growing risks of supply-chain attacks and law enforcement impersonation in cybercrime.
INCIDENT DETAILS -
TYPE
Data Breach, Extortion
MOTIVATION
Financial gain
IMPACT
Data Compromised: Passports, driving licenses, identity verification images, transaction historiesBrand Reputation Impact: Potential reputational damageIdentity Theft Risk: High
DATA BREACH
PassportsDriving licensesIdentity verification imagesTransaction historiesNumber Of Records Exposed: 680Sensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
SEPTEMBER 2026
477Before Incident
Breach
13 Sep 2026Revolut
Revolut: Revolut confirms customer data breach

Revolut Customer Data Breach

428After Incident
CRITICAL-49
REV1789323856
Revolut Confirms Customer Data Breach Amid Rising Cybersecurity Concerns Revolut, the UK-based fintech giant, has confirmed a customer data breach, exposing sensitive information in a recent cybersecurity incident. While the company has not disclosed the full scope of the breach, early reports suggest that personal details including names, addresses, and partial payment card data may have been compromised. The breach was detected following unusual activity within Revolut’s systems, prompting an immediate investigation. The company has assured customers that no passwords or full payment card details were accessed, though the incident underscores ongoing vulnerabilities in digital financial services. This breach follows a series of high-profile cyberattacks targeting fintech firms, raising concerns about data protection in an increasingly digital banking landscape. Revolut, which serves over 35 million customers globally, has not yet provided a timeline for the incident or identified the attackers. As investigations continue, the breach serves as a reminder of the persistent threats facing financial institutions and their customers. Further details on the impact and response are expected in the coming days.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Personal details including names, addresses, and partial payment card dataBrand Reputation Impact: Underscores ongoing vulnerabilities in digital financial servicesPayment Information Risk: Partial payment card data exposed
DATA BREACH
NamesAddressesPartial payment card dataSensitivity Of Data: Sensitive personal and financial informationPersonally Identifiable Information: Names, Addresses
SEPTEMBER 2026
526Before Incident
Breach
12 Sep 2026Revolut
Revolut: Revolut Gave Customer Data to Scammers After Fake Government Requests

Revolut Discloses Sensitive Customer Data After Falling for Government Domain Spoofing Scam

428After Incident
CRITICAL-98
REV1789223034
Revolut Discloses Sensitive Customer Data After Falling for Government Domain Spoofing Scam Revolut, the UK-based digital banking and fintech platform, inadvertently shared highly sensitive customer information with an unauthorized third party after being deceived by fraudulent requests sent via a legitimate government agency’s email domain. The incident, which did not involve a direct breach of Revolut’s systems, occurred when attackers used an unauthorized email account with valid domain authentication credentials to impersonate the agency. The exposed data included full names, dates of birth, postal and email addresses, phone numbers, and occupations. More critically, the attackers obtained copies of passports, driving licenses, and facial verification images collected during Revolut’s identity checks. Financial records such as account statements, IBANs, transaction histories (including Bitcoin transactions), and withdrawal details were also disclosed. Revolut confirmed that biometric facial telemetry remained secure. Among those notified was former Mt. Gox CEO Mark Karpelès, who shared excerpts of the email on X. Blockchain investigator ZachXBT reported the breach appeared to affect a limited number of users, potentially targeting high-net-worth individuals, though Revolut has not confirmed this. The company has not disclosed the total number of affected customers, the timeline of the data release, or whether the stolen records were used elsewhere. Revolut described the attack as a “sophisticated external impersonation” and stated it fulfilled the requests under the belief they were legitimate. After verifying with the government agency, Revolut discovered the fraud, blocked the email address, and alerted authorities, regulators, and impacted customers. The company emphasized that its systems and customer funds remained unaffected. This incident follows previous security issues at Revolut, including a 2023 flaw in its US payment system that led to $23 million in losses (with $20 million unrecovered) and a 2022 breach linked to the Lapsus$ hacking group. Unlike traditional data breaches, this case highlights the risks of social engineering attacks exploiting trusted communication channels.
INCIDENT DETAILS -
TYPE
Social Engineering / Impersonation Scam
IMPACT
Data Compromised: Highly sensitive customer informationBrand Reputation Impact: YesIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Full namesDates of birthPostal and email addressesPhone numbersOccupationsPassport copiesDriving licensesFacial verification imagesAccount statementsIBANsTransaction histories (including Bitcoin transactions)Withdrawal detailsSensitivity Of Data: HighData Exfiltration: YesData Encryption: No (biometric facial telemetry remained secure)Passport copiesDriving licensesFacial verification imagesAccount statementsTransaction recordsPersonally Identifiable Information: Yes
AUGUST 2026
519Before Incident
JULY 2026
605Before Incident
Breach
25 Jul 2026Revolut
Revolut: Threat Actor Claims Revolut Data Breach Exposes Financial Records of 75 Million Users

Alleged Revolut Data Breach Claims Impact Over 757 Million Users

517After Incident
CRITICAL-88
REV1785327822
Alleged Revolut Data Breach Claims Impact Over 757 Million Users A threat actor has claimed to possess and sell a massive dataset allegedly tied to fintech company Revolut, potentially affecting over 757 million users. The claim, shared by the CyberWatch threat intelligence account on X (July 25, 2026), suggests the dataset includes sensitive customer and financial data, though its authenticity remains unverified. The purported breach may contain payment card details, user credentials, device information, customer profiles, and account records, along with multiple CSV files of user data. However, key details such as whether the data is current, unique, or sourced from Revolut directly remain unclear. The figure of 757 million could represent duplicates, scraped data, or a mix of legitimate and fabricated records. If confirmed, the exposure could enable credential-stuffing attacks, account takeovers, phishing, social engineering fraud, and identity theft. Payment card data, if included, might also lead to unauthorized transactions, though it is unknown whether full card details (e.g., CVV codes) are present. Revolut has not publicly confirmed the breach, and security experts caution that such claims often involve exaggerated or repackaged data. Independent verification such as analyzing sample records for freshness, consistency, and ties to Revolut would be required to confirm the breach’s validity. As of now, the dataset remains unverified, and no official statement from Revolut has been issued. The incident underscores the risks of unverified breach claims in cybercriminal marketplaces.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain
IMPACT
Data Compromised: Payment card details, user credentials, device information, customer profiles, account recordsBrand Reputation Impact: PotentialLegal Liabilities: PotentialIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Payment card detailsUser credentialsDevice informationCustomer profilesAccount recordsNumber Of Records Exposed: 757000000Sensitivity Of Data: HighData Exfiltration: ClaimedCSVPersonally Identifiable Information: Yes
JUNE 2026
597Before Incident
MAY 2026
593Before Incident
APRIL 2026
591Before Incident
MARCH 2026
632Before Incident
Breach
01 Mar 2026Revolut
Revolut: Revolut Data Breach Via Fake Government Requests – What We Know So Far

Revolut Data Breach Exposes Sensitive Customer Records via Fraudulent Government Requests

583After Incident
CRITICAL-49
REV1789446290
Revolut Data Breach Exposes Sensitive Customer Records via Fraudulent Government Requests Revolut, the British fintech firm, has confirmed a data breach in which an unauthorized third party obtained sensitive customer records by submitting fraudulent information requests through an email address using a legitimate government agency’s domain. Unlike traditional cyberattacks, the breach did not involve compromising Revolut’s app or banking infrastructure. Instead, the attacker exploited trust in an apparently authentic government communication, leading to the release of customer data through an established disclosure process. The fraudulent request originated from an email account under an unnamed government agency’s official domain, carrying valid domain-authentication credentials (SPF, DKIM, and DMARC). Revolut processed the request under the assumption it was legitimate, later characterizing the incident as a “sophisticated external impersonation scam.” While the company confirmed that its systems and customer funds remained unaffected, the breach exposed a wide range of sensitive data. Affected records included full names, dates of birth, occupations, postal and email addresses, phone numbers, passport or driver’s license copies, facial images from onboarding, account statements (IBANs, opening dates, wallet references), withdrawal records, and complete transaction histories including Bitcoin activity. Revolut stated that biometric facial telemetry was not compromised. The combination of verified identity documents and financial details poses significant risks for identity fraud, phishing, and targeted extortion. Revolut described the number of affected customers as “limited” but did not disclose the exact figure, the compromised government agency, the duration of the breach, or whether the incident was confined to a single country. However, crypto investigator ZachXBT suggested the operation may have targeted high-net-worth users. Separately, a threat actor using the alias “IAmNotAVillain” claimed that multiple Italian law-enforcement departments were compromised and that the breach lasted six months, allegedly yielding 147 GB of data. These claims, including a circulated screenshot showing archives labeled “Document Revolut,” remain unverified. Revolut stated it blocked the fraudulent email address upon detection and notified the relevant government agency, law enforcement, data-protection authorities, and financial regulators. While the company emphasized that its systems were not breached, the exposure of durable identity documents and financial records creates long-term risks for affected customers. The incident underscores a critical vulnerability in government-data-request workflows: authenticated email alone is insufficient for high-risk disclosures. Organizations handling such requests should implement additional safeguards, including independent verification, case-number validation, dual approval, anomaly detection, and strict data minimization. The full scope of the breach including the compromised agency, duration, and victim count remains unclear as investigations continue.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data exfiltration for identity fraud, phishing, or targeted extortion
IMPACT
Data Compromised: Full names, dates of birth, occupations, postal and email addresses, phone numbers, passport/driver’s license copies, facial images, account statements (IBANs, opening dates, wallet references), withdrawal records, transaction histories (including Bitcoin activity)Operational Impact: Reputational damage; regulatory scrutiny; customer trust erosionBrand Reputation Impact: High (exposure of sensitive financial and identity data)Legal Liabilities: Potential (regulatory violations, customer lawsuits)Identity Theft Risk: High (verified identity documents and financial details exposed)Payment Information Risk: High (IBANs, transaction histories, and withdrawal records exposed)
DATA BREACH
Personally Identifiable Information (PII)Financial DataIdentity DocumentsTransaction HistoriesSensitivity Of Data: High (government-verified identity documents, financial records)Data Exfiltration: Yes (147 GB claimed by threat actor, unverified)PDF (passport/driver’s license copies)Images (facial onboarding photos)Text (transaction records, account statements)Personally Identifiable Information: Full names, dates of birth, postal/email addresses, phone numbers, passport/driver’s license copies, facial images
FEBRUARY 2026
632Before Incident
JANUARY 2026
629Before Incident
DECEMBER 2025
622Before Incident
NOVEMBER 2025
621Before Incident
OCTOBER 2025
617Before Incident
JULY 2025
651Before Incident
Breach
01 Jul 2025Revolut
Revolut: Revolut’s data breach shows institutions can be at risk even when not directly compromised

Revolut Data Breach Exposes 680 Customers in Sophisticated Social Engineering Attack

600After Incident
CRITICAL-51
REV1789562336
Revolut Data Breach Exposes 680 Customers in Sophisticated Social Engineering Attack Revolut, one of Europe’s leading digital financial services providers, suffered a data breach after cybercriminals impersonated government officials using a compromised legitimate email account. The attackers, posing as law enforcement or regulatory authorities, convinced Revolut to disclose sensitive customer information including passport details, identity documents, home addresses, bank account numbers, and cryptocurrency activity affecting approximately 680 individuals. Unlike traditional breaches, the attackers did not infiltrate Revolut’s core systems. Instead, they exploited trust in official communication channels, demonstrating how financial institutions remain vulnerable even when their internal security remains intact. The fraudulent requests, sent over several months, targeted customers with significant cryptocurrency holdings, primarily in Switzerland and France, though data from 31 other European countries was also involved. The hackers later demanded a ransom, threatening to publish the stolen information. Revolut blocked the fraudulent email address, reported the incident to authorities, and confirmed that its internal systems and customer funds were not compromised. The attack originated from a hijacked Italian government email system used for secure legal communications, underscoring the growing threat of credential-based impersonation. The incident highlights a shift in cybercriminal tactics, where social engineering and AI-enabled fraud bypass traditional security measures. Reports from the Federal Reserve and Visa indicate a rise in such attacks, with scams accounting for nearly $1 billion in fraudulent activity in late 2025. For digital banks like Revolut, balancing responsiveness to legitimate regulatory requests with fraud prevention has become increasingly complex. The UK’s Information Commissioner’s Office (ICO) has launched an investigation into the breach, though no regulatory violations have been confirmed. The ICO’s guidance emphasizes the need for robust breach detection and timely notification of affected individuals when high-risk data is exposed. The breach also raises broader questions about regulatory adaptation to evolving threats. As criminals leverage deepfakes, synthetic identities, and AI-generated messages, financial institutions may need to adopt decentralized identity verification, blockchain-based credentials, and hyperscale AI for real-time threat detection. The Bank for International Settlements (BIS) has urged regulators to evolve frameworks alongside technological advancements, ensuring defenses keep pace with emerging risks. The incident serves as a reminder that security must extend beyond perimeter defenses, requiring stricter verification of external requests and controlled disclosure of sensitive data.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial gain (ransom demand, potential sale of data on dark web)
IMPACT
Data Compromised: Passport details, identity documents, home addresses, bank account numbers, cryptocurrency activityBrand Reputation Impact: HighLegal Liabilities: Potential (under investigation by UK ICO)Identity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Passport detailsIdentity documentsHome addressesBank account numbersCryptocurrency activityNumber Of Records Exposed: 680Sensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
MAY 2025
716Before Incident
Breach
01 May 2025Revolut
Revolut: Revolut Alleged Data Breach – Hackers Claiming to Access Over 75 Million Users’ Records

Revolut Alleged Data Breach of 75 Million User Records

645After Incident
CRITICAL-71
REV1785335106
Revolut Faces Alleged Data Breach of 75 Million User Records Revolut is investigating claims that a threat actor is selling a database containing records of over 75 million users on a cybercrime forum. The company, however, has stated it has found no evidence of a new breach. The dataset, advertised for approximately $500, includes partial card details (last four digits, card type, expiration dates, and status), email addresses, full names, phone numbers, physical addresses, account identifiers, device information, and hashed credentials (bcrypt or argon2id). Security researchers who reviewed samples noted the data could enable targeted phishing and identity theft campaigns. Initial analysis suggests the records may span up to May 2025, though investigators have not linked them to any prior Revolut incidents. The company has dismissed the claims, stating the alleged breach lacks verifiable evidence, such as a confirmed record count or technical proof of compromise. Revolut maintains its security systems show no signs of unauthorized access. This follows a 2022 breach where a social engineering attack exposed data for roughly 50,150 users less than 0.2% of its user base at the time. If verified, the current leak would represent a far larger exposure, significantly increasing risks of financial fraud and phishing for Revolut’s global customer base. The investigation remains ongoing.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain
IMPACT
Data Compromised: Partial card details (last four digits, card type, expiration dates, status), email addresses, full names, phone numbers, physical addresses, account identifiers, device information, hashed credentialsBrand Reputation Impact: Potential significant impact due to scale of alleged breachIdentity Theft Risk: HighPayment Information Risk: Moderate (partial card details exposed)
DATA BREACH
Partial card detailsEmail addressesFull namesPhone numbersPhysical addressesAccount identifiersDevice informationHashed credentialsNumber Of Records Exposed: 75,000,000 (alleged)Sensitivity Of Data: HighData Exfiltration: Alleged (data advertised for sale on cybercrime forum)Data Encryption: Hashed credentials (bcrypt or argon2id)Personally Identifiable Information: Yes
NOVEMBER 2024
745Before Incident
Breach
01 Nov 2024Revolut
Revolut: Revolut Data Breach Exposes Passports, Selfies and Financial Records After Fraudsters Impersonate Government Officials

Revolut Data Breach Due to Sophisticated Impersonation Scam

702After Incident
CRITICAL-43
REV1789468579
Revolut Discloses Data Breach After Sophisticated Impersonation Scam Revolut, Europe’s largest fintech company, has confirmed a significant data breach after fraudsters impersonating government officials convinced the company to release highly sensitive customer information. The incident, described as a “sophisticated external impersonation scam,” did not involve a direct attack on Revolut’s banking infrastructure. Instead, attackers exploited trust in an authentic government email domain to submit fraudulent requests for customer data, which were initially treated as legitimate. Approximately 700 customers were notified following an internal investigation, though Revolut characterized the number of affected individuals as “very limited.” The compromised data includes names, dates of birth, postal and email addresses, phone numbers, account statements, IBANs, withdrawal records, verification photographs, passports, driving licenses, and detailed transaction histories including Bitcoin activity for some users. ### Extortion Threats and Regulatory Scrutiny The attackers, who have not been publicly identified, reportedly demanded a ransom to prevent the public release of the stolen data, according to the Financial Times. Unlike traditional ransomware attacks, this incident involved extortion based on data obtained through social engineering rather than system encryption. The UK’s Information Commissioner’s Office (ICO) has launched an investigation into the breach, examining how the requests were validated, whether Revolut’s safeguards were sufficient, and whether proper steps were taken to protect affected customers. The ICO will assess whether Revolut complied with UK GDPR requirements, including timely breach notification and data minimization principles. Revolut has stated that customer funds and internal systems remain unaffected, but the exposed information particularly identity documents and financial records poses long-term risks. Criminals could use the data for targeted phishing, account takeovers, or identity fraud, leveraging personal details to craft convincing impersonation attempts. Some reports suggest the breach may have targeted high-net-worth individuals, including cryptocurrency holders, raising concerns about physical security risks for affected customers. ### A Breach Without a Traditional Hack This incident highlights a growing threat: data breaches enabled by procedural weaknesses rather than technical vulnerabilities. Financial institutions routinely process requests from law enforcement and government agencies, often under legal compulsion or emergency authority. Attackers exploit this by: - Using compromised or spoofed government email domains to lend credibility to fraudulent requests. - Fabricating urgency (e.g., claims of kidnappings, terrorist threats, or missing persons) to bypass standard verification. - Leveraging stolen legal templates and official signatures to mimic legitimate documentation. The FBI warned in November 2024 about a rise in such schemes, noting that criminals trade access to government email accounts and provide step-by-step guides on crafting convincing requests. Previous cases, including breaches at Apple and Meta in 2022, demonstrated how even well-secured companies can be manipulated when attackers gain access to trusted communication channels. ### Key Unanswered Questions Revolut has not disclosed: - Which government agency’s email domain was exploited or how the account was compromised. - When the fraudulent requests began or how many were processed. - Whether multiple employees or teams were involved in approving the disclosures. - What supporting documentation, if any, accompanied the requests. The incident underscores the need for multi-layered verification when handling sensitive data requests. Email domain authentication (SPF, DKIM, DMARC) alone is insufficient organizations must independently confirm the identity, authority, and legal basis of requests, particularly when they involve broad or highly sensitive data. As Revolut expands its global customer base now exceeding 80 million users the breach serves as a reminder that procedural security is as critical as technical defenses. The ICO’s investigation will determine whether Revolut’s controls were adequate, but the case reflects a broader challenge: how to balance compliance with official requests while preventing exploitation by criminals who weaponize institutional trust.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion, Financial Gain
IMPACT
Data Compromised: Names, dates of birth, postal and email addresses, phone numbers, account statements, IBANs, withdrawal records, verification photographs, passports, driving licenses, transaction histories (including Bitcoin activity)Brand Reputation Impact: HighLegal Liabilities: Potential GDPR violations under investigation by ICOIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Personally Identifiable Information (PII)Financial RecordsIdentity DocumentsTransaction HistoriesNumber Of Records Exposed: 700 customersSensitivity Of Data: HighData Exfiltration: YesPDF (account statements)Images (passports, driving licenses, verification photographs)Text (transaction histories)Personally Identifiable Information: Names, dates of birth, postal and email addresses, phone numbers, IBANs, verification photographs, passports, driving licenses
JANUARY 2024
764Before Incident
Cyber Attack
01 Jan 2024Revolut
N26 and Revolut: French Fintech Accounts Used to Launder Stolen Funds Before Detection

French Freelancer Fintech Accounts Exploited for Large-Scale Money Laundering

725After Incident
CRITICAL-39
N26REV1776860884
French Freelancer Fintech Accounts Exploited for Large-Scale Money Laundering Cybercriminals are increasingly hijacking French freelancer fintech accounts to launder stolen funds at high speed, often moving money within minutes before banks or victims detect the fraud. Platforms like Revolut, Wise, and N26 designed for fast onboarding, light-touch KYC, and instant SEPA transfers have become prime targets due to their business-level payment capabilities, despite being tied to individual users. In 2024, credit transfer fraud in the European Economic Area (EEA) reached €2.5 billion, with victims absorbing roughly 85% of losses. These accounts are more attractive to criminal networks than standard consumer accounts, as they enable cross-border transfers and payment processing under the guise of legitimate business activity. ### Industrial-Scale Mule Account Operations Fraudsters acquire verified freelancer accounts through a sophisticated, multi-stage process: - Identity Harvesting: Phishing sites and fake financial services (e.g., bogus mortgage portals) collect real French personal data. - SIM Farm Infrastructure: Criminals use SIM modem farms to generate French IP addresses and phone numbers, rotating connections to evade detection. - Social Engineering KYC: Victims are tricked into completing verification, making the process appear compliant to fintech platforms. - Account Handoff: Once verified, accounts are transferred to fraud rings via mobile apps, creating distinct device profiles in telemetry. Dark web markets, including the ASGARD network and actor @astarta_seller1, specialize in selling these accounts, with premium French freelancer profiles fetching $450–$700. France is the primary target, followed by Germany, Spain, Italy, Poland, and the UK. ### Detection Challenges & Broader Impact The fraud ecosystem exploits gaps in point-in-time checks, as each stage of the process sign-up, KYC, and login appears legitimate in isolation. Effective defense now requires linking signals across the full account lifecycle, including infrastructure, subnet continuity, and cross-account connections. The 2025 EBA/ECB Payment Fraud Report highlights the rapid growth of credit transfer fraud, driven by the abuse of instant payment rails. For risk and compliance teams, freelancer fintech accounts must be monitored as part of broader fraud networks, not just individual users.
INCIDENT DETAILS -
TYPE
Money Laundering, Fraud, Account Takeover
MOTIVATION
Financial gain, Money laundering
IMPACT
Financial Loss: €2.5 billion (2024 EEA credit transfer fraud)Data Compromised: French personal data, Freelancer account credentialsSystems Affected: Fintech platforms (Revolut, Wise, N26), Payment rails (SEPA)Operational Impact: Exploitation of instant payment rails, Fraudulent cross-border transfersBrand Reputation Impact: Potential erosion of trust in fintech platformsIdentity Theft Risk: High (PII harvested and exploited)Payment Information Risk: High (fraudulent transactions)
DATA BREACH
Type Of Data Compromised: Personal Identifiable Information (PII), Account credentialsSensitivity Of Data: High (used for fraud and money laundering)Personally Identifiable Information: Yes (French personal data)
JANUARY 2023
787Before Incident
Cyber Attack
01 Jan 2023Revolut
N26, Revolut and Wise: Cybercriminals Exploit French Fintech Accounts to Move Stolen Money Before Detection

Fraud Networks Exploit Fintech Platforms in France to Launder Stolen Funds

748After Incident
CRITICAL-39
N26REVWIS1776889641
Fraud Networks Exploit Fintech Platforms in France to Launder Stolen Funds Organized fraud networks in France are deploying a sophisticated scheme to launder stolen money through fake business accounts on freelancer fintech platforms like Revolut, Wise, and N26. These platforms, designed for fast account openings and seamless transactions, have become prime targets due to their business-grade payment infrastructure, including SEPA transfers and invoicing. The operation, tracked as "Bastardaseller" part of the larger ASGARD fraud network specializes in creating and selling verified European business accounts on dark web marketplaces for $200 to $1,000 each. These accounts, known as mule accounts, enable fraudsters to move funds rapidly via instant payment rails, often before detection. In France, nearly 1 in 5 sign-up users was identified as a mule account, with the true scale likely higher. The scheme operates in three phases: 1. Phishing for PII – Fraudsters run phishing campaigns, such as fake mortgage consultation services, to collect victims' personal data. 2. Account Registration – Stolen PII is used to open accounts, with operators masking their location using SIM modem farms to generate French IP addresses and phone numbers. 3. Operational Handover – Once KYC is completed, control shifts to the fraud network via mobile apps, with subnet continuity linking the new login to the original sign-up infrastructure. According to the EBA-ECB Joint Report on Payment Fraud, credit transfer fraud losses in the European Economic Area reached $2.5 billion in 2023, a 25% increase from the previous year, with mule accounts as the primary driver. Detection remains challenging, as the fraud only becomes visible when analyzing the full account lifecycle rather than isolated transactions. Fintech platforms are urged to monitor MVNO IP addresses, sign-up velocity patterns, and device downgrades between KYC and operational phases to disrupt these networks. The attack underscores the growing threat of structured fraud operations exploiting digital financial services.
INCIDENT DETAILS -
TYPE
Fraud, Money Laundering
MOTIVATION
Financial gain, Money laundering
IMPACT
Financial Loss: $2.5 billion (credit transfer fraud losses in EEA, 2023)Data Compromised: Personally Identifiable Information (PII)Systems Affected: Fintech platforms (Revolut, Wise, N26)Operational Impact: Increased fraud detection challenges, exploitation of payment railsBrand Reputation Impact: Potential reputational damage to fintech platformsIdentity Theft Risk: High (stolen PII used for account creation)Payment Information Risk: High (SEPA transfers, instant payments)
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII)Sensitivity Of Data: High (used for account creation and fraud)Personally Identifiable Information: Yes (stolen via phishing)
SEPTEMBER 2022
800Before Incident
Cyber Attack
01 Sep 2022Revolut
Revolut

Revolut Data Breach

781After Incident
CRITICAL-19
REV101719922
Revolut suffered from a cyber attack incident that compromised the personal details of more than 50,000 people. An unauthorized third party had access to some of their information as a result, including contact and transactional details, card information, pin numbers, and passwords were not collected. Revolut advised affected customers to be extra cautious as there may be an increased risk of impersonation or fraud.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
contact detailstransactional detailscard informationIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
contact detailstransactional detailscard informationSensitivity Of Data: HighPersonally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Revolut ?
?
What was Revolut's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Revolut's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Revolut's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Revolut's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Revolut's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Revolut's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Revolut's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Revolut's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Revolut's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Revolut's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Revolut's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Revolut's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Revolut ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Revolut's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?