Revolut Data Breach: Maltese Customers Are Among Those Affected

While much of the Maltese media appears to be sleeping through yet another important international story, a major data breach involving Revolut has been making headlines across Europe. What now makes the story directly relevant to us is that Maltese Revolut customers are among those whose details were exposed.
And perhaps the most extraordinary aspect is this: the person responsible did not even need to hack Revolut’s systems.
Instead, the fraudster sent requests for customer information from what appeared to be an official government-agency email account. Revolut apparently accepted these requests as genuine and supplied the information.
Read that again: the hacker did not have to break into Revolut’s computer system. Revolut was deceived into handing over the information itself.
At first, reports in the British press focused on around 700 UK customers whose information had been disclosed. But it later emerged that the breach was much wider, affecting customers in other European countries, particularly France and Italy.

And now Malta has entered the picture.
Maltese customers are also among those whose personal information was obtained.
This is particularly serious because Revolut is extraordinarily widely used in Malta. For many people, it is not simply an occasional payment application but an everyday financial service used for transfers, purchases, travel and savings.
The information exposed in the wider breach reportedly includes highly sensitive personal and financial data, potentially including names, dates of birth, addresses, telephone numbers, email addresses, identification documents, photographs used for identity verification, IBAN details, bank statements, withdrawal records and transaction histories.
Revolut has stressed that its internal systems were not hacked and that customers’ funds were not compromised. But this does not make the incident insignificant. On the contrary, it raises a different and equally troubling question: how could such sensitive customer information be released merely because a request appeared to come from an official authority?
The Malta dimension now deserves immediate attention.
How many Maltese customers were affected? What information concerning them was handed over? Have all those customers been informed? Have the Maltese authorities responsible for data protection and financial regulation been notified? And what steps are being taken to ensure that information of this kind cannot again be released through fraudulent official requests?
Malta is part of the breach, and Maltese customers deserve to know exactly what happened to their data.
