HomeReview
Share

How might investors view the incident involving the leak of Revolut customer data?

Mikhail Tegin

Mikhail Tegin

Oninvest Reporter
Yulia Petrova

Yulia Petrova

A lawyer warns that what happened to Revolut could happen to any company, regardless of its jurisdiction. Photo: Unsplash / AltumCode

A lawyer warns that what happened to Revolut could happen to any company, regardless of its jurisdiction. Photo: Unsplash / AltumCode

Could the incident involving the transfer of Revolut customer data to cybercriminals affect the company's valuation, and what consequences will it have for the neobank's customers?

The Data Breach and Its Consequences for Revolut

Reports that Revolut had leaked the data of at least 680 of its customers to scammers first appeared in the media on September 12—TechCrunch was the first to break the story. The fintech company itself acknowledged the data breach. The scammers obtained customers’ dates of birth, mailing and email addresses, phone numbers, and copies of documents, including passports and driver’s licenses. According to the Financial Times, the attackers targeted Revolut customers with large cryptocurrency holdings by analyzing the blockchain.

A data breach affecting hundreds of Revolut customers occurred as the neobank was actively expanding into Western markets / Photo: Veja/Shutterstock.com

Hack of the Italian State Post Office, the Hunt for "Whales": The FT Learns Details of the Revolut Data Breach

Revolut itself stated that it had detected “a complex external fraud scheme involving impersonation of another person or organization.” The bank then blocked the IP address from which the hackers sent the request and reported the incident to the government agency on whose behalf the attackers were posing, as well as to law enforcement, the data protection regulator, and financial authorities.

Revolut is a privately held fintech company that is preparing for an IPO (no earlier than 2028) and is considering a dual listing in New York and London. Its goal is to become a global bank with a valuation of $150–200 billion by that time. In July of this year, it conducted a secondary offering at a price of $2,017 per share and a total valuation of $115 billion.

Since the company is privately held, it is impossible to directly assess the incident’s impact on its current market value. However, there are indirect indications—according to Forge, Revolut’s estimated pre-IPO share price as of September 11 has fallen by approximately 3.4% to date, to $2,125.

Photo: AltumCode / Unsplash

50% Jump: Revolut Begins Secondary Share Offering at a Valuation of $115 Billion

On the Polymarket platform, about a week after news of the incident broke, the probability that Revolut would reach a valuation of $150 billion by January 1, 2027, plummeted—from 53% in early September to 8% (as of September 17). It currently stands at 47%. During the same week, the probabilities for valuations of $175 billion and $200 billion remained essentially unchanged.

On stock exchanges, bad news can be reflected in a stock’s price almost instantly, but private companies lack such a mechanism, says venture capitalist Pavel Myasnikov. A private company may simultaneously have several offers to purchase its shares at different prices.

For her, it is the combination of long-term factors—rather than any single specific one—that matters most: investors can assess market sentiment and the results of due diligence, while also drawing on feedback from other investors and information about the founder’s reputation, Myasnikov emphasizes.

There will be some minor negative fallout from the leak, but it won't hinder the IPO in any way, so (the leak incident in this case) can be ignored

Author - Oninvest

Vadim Merkulov

Director of the Analytics Department at Freedom Finance Global

What are the potential consequences for customers?

The consequences for potentially affected customers of the neobank could be serious, warns Mark Beranzoni, a financial crime prevention specialist and founder of FinCrime Agent, who previously worked at HSBC, Standard Chartered, and Bank of America Merrill Lynch.

According to him, the availability of public blockchain data containing leaked information makes it possible to link a crypto wallet to a specific person, their address, and their documents. Even if customers’ funds were not stolen, such a dataset could be used by attackers in the future for targeted phishing, account takeover attempts, extortion, and, in the case of large crypto asset holders, could potentially pose risks to their physical safety, says Beranzoni.

What Lawyers and Financial Security Experts Say

In a statement to Oninvest, Revolut noted that fraud schemes involving impersonation “are becoming increasingly sophisticated: attackers combine in-depth research on their targets, convincing pretexts, and carefully crafted messages to create extremely plausible social engineering campaigns.”

"Instead of exploiting technical vulnerabilities, attackers are increasingly seeking to exploit trust and existing business processes," said a bank spokesperson.

The Reggio di Calabria Public Prosecutor's Office has already launched an investigation, and the Italian data protection authority has asked banks to check their systems for any unusual messages from the same certified email address used by the hackers and to determine whether they sent similar requests to other financial institutions.

Ramis Abyanov, managing partner at ZenitLegal, notes that Revolut should have verified not only the domain of the entity sending the requests, but also whether the request itself was properly formatted and whether the person who signed it had the authority to access the data.

Government agencies may request access to customer information not only for the purpose of investigating a criminal case, the lawyer explains: such information may be needed when examining third-party transactions, during tax audits, financial supervision, or AML checks. However, even a properly drafted request does not grant a government agency access to all client information. The bank is entitled to disclose only the amount of information that is strictly necessary for the audit or investigation.

Hackers who call themselves ImNotAVillain have claimed responsibility for the Revolut customer data breach. Photo: Unsplash / appshunter.io

How Could the Revolut Data Breach Have Been Avoided? A Financial Crime Expert Weighs In

In the case of requests from foreign authorities, the procedure may be even more complicated: for example, a court order or a request from financial intelligence agencies or tax authorities may be required.

“In Italy, government agencies have broad access to information held by banks. But in some cases, a single request is not enough; a court order is required,” agrees Maria Suskaya, an attorney at the Moscow office of Sokolov, Trusov & Partners.

She believes that the Revolut case could spark further discussion about the rules governing government agencies’ access to banking information in Italy.

Ekaterina Kharchenko, an attorney and senior lawyer at Criminal Defense Law Firm, notes that leaks of personal data to malicious actors—who use requests from government and law enforcement agencies as a cover— — are a direct result of a situation in which the requirements for government agencies when transferring sensitive information in everyday life are lower than, for example, those for requests from business partners or consumers.

As a result, Kharchenko believes that a similar situation could potentially arise for any company, regardless of its jurisdiction.

This article was AI-translated and verified by a human editor

Share

Trending

Stock Screener
Buy
Sell






















Small Caps
Investment and Finance News