Revolut has confirmed that a social engineering attack allowed a threat actor to impersonate a government official and trick employees into disclosing sensitive customer data. The breach, affecting approximately 50,000 users, exposes critical vulnerabilities in human-led security procedures, with passport copies posing a significant identity theft risk for Hong Kong customers.

The incident unfolded over several weeks between August and September 2023. In a highly targeted scheme, a criminal posed as a government agency in communications with Revolut staff. This manipulation was successful enough to convince authorised personnel to release a trove of personal data, bypassing the company's technical security defences.

For those affected, the compromised information could range from basic contact details to highly sensitive financial records. According to disclosures, the data included names, emails, phone numbers, and addresses. For a subset of users, the breach was more severe, encompassing Revolut account details, transaction statements, and, crucially, passport images. A small number also had partial payment card information exposed.

Revolut has stated that its security team identified the unauthorised data sharing and shut it down "within hours," initiating an investigation with external cybersecurity experts. The company has attributed the success of the attack to its "highly targeted and sophisticated" nature, exploiting the human element of trust.

This event starkly illustrates that even robust technical infrastructure can be circumvented by targeting people, not software. Social engineering preys on compliance and trust in perceived authority, turning internal procedures into a point of weakness. For Hong Kong users, where passports serve as a primary financial identifier, this specific data exposure creates a direct pathway for sophisticated identity fraud.

Actionable Steps for Affected Hong Kong Users:

Revolut is notifying impacted customers. If you are a user, consider these immediate steps:

  1. Verify Communications: Be skeptical of any unsolicited contact. Do not provide personal data in response to unexpected messages. Verify any claims by contacting Revolut directly through its official app or known support channels.
  2. Monitor Accounts: Vigilantly review your Revolut and linked bank statements for any unauthorised activity. Enable all security features, such as transaction alerts and two-factor authentication.
  3. Report Suspected Fraud: If you detect fraudulent activity, file a report with the Hong Kong Police Force's Cyber Security and Technology Crime Bureau.
  4. Secure Documents: If you have evidence or suspicion that your passport information has been misused, report this to the Hong Kong Immigration Department for potential cancellation and replacement. Alert your other financial institutions about the risk of identity theft.

The incident underscores a dual responsibility. Organisations must invest in continuous, anti-social engineering training and build stringent internal verification protocols. Individuals, in turn, must assume that their data may be at risk and monitor their accounts with heightened vigilance.


Revolut 已證實一宗社會工程攻擊事件,讓威脅行為者得以冒充政府官員,欺騙公司職員洩露敏感的客戶資料。這次外洩影響約五萬名用戶,暴露出以人為主的保安流程存在關鍵漏洞,當中護照副本更對香港用戶構成重大的身份盜用風險。

事件發生於二零二三年八月至九月期間,歷時數週。在一次高度針對性的騙局中,一名犯罪分子在與 Revolut 職員的溝通中冒充某政府機構。這種操縱手法相當成功,足以說服獲授權的人員釋放大量個人數據,從而繞過公司的技術保安防線。

對受影響者而言,被洩露的資訊可能從基本的聯絡詳情到極其敏感的財務紀錄不等。據披露,外洩數據包括姓名、電郵、電話號碼及地址。對部分用戶而言,外洩情況更為嚴重,涉及 Revolut 帳戶詳情、交易紀錄,以及至關重要的護照影像。另有少數用戶的部分支付卡資訊亦被曝光。

Revolut 表示,其保安團隊已識別未經授權的數據分享並在「數小時內」予以制止,同時與外部網絡安全專家展開調查。公司將這次攻擊成功歸因於其「高度針對性與複雜性」,利用了人際信任這個環節。

此事件鮮明地說明,即使再穩健的技術基礎設施,也可能因針對人而非軟件而被規避。社會工程手段利用人們對所謂權威的服從與信任,將內部流程轉化為薄弱環節。對香港用戶而言,護照作為主要的財務身份證明文件,這次特定的資料外洩為精密的身分詐騙行為打開了直接通道。

受影響香港用戶的跟進步驟:

Revolut 正在通知受影響的客戶。如果你是用戶,請考慮以下即時措施:

  1. 核實通訊: 對任何未經索取的聯絡保持警惕。切勿因收到意料之外的訊息而提供個人資料。請透過 Revolut 官方應用程式或已知的支援渠道直接聯繫公司,以核實任何聲稱。
  2. 監察帳戶: 仔細查閱你的 Revolut 及關聯銀行月結單,留意任何未經授權的活動。啟用所有安全功能,例如交易提示及雙重認證。
  3. 舉報可疑詐騙: 若你發現欺詐活動,請向香港警務處網絡安全及科技罪案調查科提出報告。
  4. 保障文件安全: 若你有證據或懷疑你的護照資訊被盜用,請向香港入境事務處報告,以考慮是否需要取消及補領。同時,應就身分盜用風險提醒你的其他金融機構。

此事件突顯了雙重責任。機構必須投資於持續的反社會工程培訓,並建立嚴格的內部核實協議。個人方面,則必須假定自己的數據可能面臨風險,並以更高警惕性監察自己的帳戶。

新聞來源 / Original News Source