The Fin Desk Brief
▸Visa Data: Nearly 17% of Stablecoin-Linked Card Volume Flows Through Commercial Programmes▸Coinbase Launches Retail IPO Access, Debuts Feature With Oura Smart-Ring Offering▸Global Payments posts 12% adj. EPS growth in Q4 2024, launches $250m buyback amid Worldpay deal▸Adyen Nominates Ex-Klarna CFO Niclas Neglen as Finance Chief from February 2027▸Visa Targets B2B Stack With ERP Integration, Commercial Hub and Stablecoin Settlement▸Revolut Cyberattack Exposed Data of 50,000-Plus Customers; Lithuanian Regulator Opens Inquiry▸AI Deepfakes Can Now Defeat All Four Layers of Bank KYC Controls, Research Finds▸Fintechs on Course to Overtake Banks as Top SME Cross-Border Payment Provider by 2028▸Worldline Connects AI Agents to Payment Ecosystem Under Agentic Commerce Push▸Visa launches VTAP platform for banks to issue fiat-backed tokens on Ethereum▸Visa Data: Nearly 17% of Stablecoin-Linked Card Volume Flows Through Commercial Programmes▸Coinbase Launches Retail IPO Access, Debuts Feature With Oura Smart-Ring Offering▸Global Payments posts 12% adj. EPS growth in Q4 2024, launches $250m buyback amid Worldpay deal▸Adyen Nominates Ex-Klarna CFO Niclas Neglen as Finance Chief from February 2027▸Visa Targets B2B Stack With ERP Integration, Commercial Hub and Stablecoin Settlement▸Revolut Cyberattack Exposed Data of 50,000-Plus Customers; Lithuanian Regulator Opens Inquiry▸AI Deepfakes Can Now Defeat All Four Layers of Bank KYC Controls, Research Finds▸Fintechs on Course to Overtake Banks as Top SME Cross-Border Payment Provider by 2028▸Worldline Connects AI Agents to Payment Ecosystem Under Agentic Commerce Push▸Visa launches VTAP platform for banks to issue fiat-backed tokens on Ethereum
FintechAnalysis

Revolut Cyberattack Exposed Data of 50,000-Plus Customers; Lithuanian Regulator Opens Inquiry

A targeted cyberattack on Revolut on 11 September 2022 exposed personal data including names and email addresses of more than 50,000 customers before the company contained the intrusion. Lithuania's State Data Protection Inspectorate has formally opened an investigation into the breach.

The Fin Desk Newsroom1 October 2026Updated 51m ago3 min read
Revolut Cyberattack Exposed Data of 50,000-Plus Customers; Lithuanian Regulator Opens Inquiry
A cracked smartphone screen displaying the Revolut logo overlaid with a padlock symbol and a red warning shield, set against a dark digital background suggesting a data breach.Leeloo The First / Pexels
Why this matters

The incident shows how rapidly a targeted intrusion can compromise tens of thousands of consumer records at a major fintech platform and trigger cross-border regulatory scrutiny.

Revolut Breach Exposed Data of More Than 50,000 Customers, Lithuanian Regulator Investigates

A cyberattack on Revolut late on Sunday 11 September 2022 exposed the personal data of more than 50,000 customers before the company identified and isolated the intrusion by early Monday 12 September, according to multiple independent reports corroborated by BleepingComputer and Which?.

The fintech, which at the time served more than 20 million customers globally — including 4.8 million in the United Kingdom, according to Which? — confirmed the incident publicly in the days that followed, describing it as a "highly targeted cyberattack."

What Was Accessed

Revolut spokesperson Michael Bodansky confirmed that "an unauthorized third party obtained access to the details of a small percentage (0.16%) of our customers for a short period of time," as reported by TechCrunch. That fraction translates to more than 50,000 individuals across Revolut's global user base.

According to TechCrunch, the exposed data included customer contact details and account data. TechCrunch's reporting specifically cited names and email addresses among the categories of personal information involved. Full payment card details and complete account numbers were not confirmed as compromised in Revolut's public statements, as reported by TechCrunch.

An unauthorised third party accessed the personal details of more than 50,000 customers in a short window before Revolut contained the breach — a reminder of how quickly targeted intrusions can move against large consumer platforms.

Revolut notified affected customers directly by email. The company stated that customers who did not receive such a notification were not impacted by the incident.

Regulatory Response

The Lithuanian State Data Protection Inspectorate, which holds supervisory jurisdiction relevant to Revolut's European operations, formally initiated an investigation into the personal data breach, according to a notice published on the regulator's own website. That investigation represents the principal confirmed regulatory action arising from the September 2022 incident documented in available sources.

Phishing Risk

Security researchers and news outlets noted that the exposure of customer contact data created conditions for downstream phishing activity. As BleepingComputer reported, the breach fuelled a new phishing wave targeting Revolut customers — a predictable consequence when contact details including email addresses are obtained by unauthorised parties and potentially exploited to craft credible-looking fraudulent communications.

Revolut customers who were not contacted by the company were told they had no cause for concern, though security practitioners generally advise vigilance for unsolicited messages following any data exposure affecting a large consumer platform.

What Remains Unverified

Reporting published elsewhere has referenced extortion threats and the alleged release of portions of stolen customer data by a threat actor following the breach. Those claims appear in secondary sources whose content could not be fully reviewed for this article and are therefore excluded from this report. Similarly, a ransom figure cited in some later coverage carries a high risk of conflation with a separate, unrelated incident and is not reported here. The precise technical attack vector — including any social-engineering or email-based method used to gain initial access — was referenced in source headlines but could not be independently confirmed from fully readable primary material and is likewise omitted.

Why It Matters

The September 2022 incident remains a significant data-security episode in the European fintech sector for several reasons grounded in the confirmed facts. A customer base of more than 20 million people means that even a breach affecting 0.16% of users translates to a substantial absolute number of individuals whose personal contact and account information was exposed, however briefly. Formal regulatory scrutiny from a national data protection authority adds legal consequence to the reputational dimension. And the documented emergence of phishing activity in the breach's aftermath illustrates how data exposures in the payments and digital-banking sector carry secondary risks that extend well beyond the initial intrusion window.


This article is based on verified facts drawn from primary regulatory sources, TechCrunch, BleepingComputer and Which?. Claims that could not be corroborated from fully reviewed sources have been omitted.

cyberattackdata breachneobank securityGDPRphishingregtech
Companies in this story
About the Author
The Fin Desk Newsroom
Newsroom

The Fin Desk Newsroom publishes verified reporting on the developments shaping fintech, payments and modern financial infrastructure.

Related Stories

Visa publishes 2025 Brazil digital-shopping index to support embedded-payments push
Fintech

Visa publishes 2025 Brazil digital-shopping index to support embedded-payments push

Visa has released the 2025 edition of its Global Digital Shopping Index for Brazil, produced with PYMNTS, positioning embedded payment functionality in apps, websites and AI environments as a structural change in retail rather than a product feature. Several data figures linked to the report remain unverified and have been withheld pending primary-source extraction.

2h ago
The Fin Desk Daily

The essential developments in modern finance

The essential developments across fintech, payments and modern finance — delivered to your inbox.

Free. No spam. Unsubscribe anytime.