Digital Bank Revolut Expands in Colombia and Switzerland while Managing Major Security and Data Breach

Revolut’s latest expansion push arrives alongside a difficult security episode that the company is still managing. The London-based digital bank said this week that Colombia’s financial supervisor had granted it an operating licence, completing the last regulatory hurdle before it can open as a locally regulated bank.

The approval is Revolut’s sixth full banking licence, after earlier authorisations in the United Kingdom, France, Australia, Lithuania and Mexico. Officials and company sources have pointed to a 2027 start in Colombia.

Roughly 200,000 people in the country are already on a waitlist.

Revolut has pledged further investment in local digital banking infrastructure and financial technology, adding tens of millions of dollars on top of earlier capital committed to the project.

A day later, Revolut confirmed it had filed for a Swiss banking licence with FINMA.

The application is under review and approval is not assured.

The firm already serves more than 1.3 million customers in Switzerland through its Lithuanian bank and a local representative office, but it cannot yet offer franc-denominated salary accounts or full Swiss deposit protection.

A license would open the door to Swiss IBANs, payroll accounts, eBill, merchant acquiring and, potentially, later products such as Pillar 3a pensions and Twint.

Revolut said it intends to invest more than 150 million Swiss francs in the market over five years and to strengthen local leadership as it builds a standalone Swiss entity.

Those growth plans coincide with the fallout from a social-engineering incident rather than a break-in of Revolut’s own systems.

The company has said an unauthorised party used a genuine government-agency email domain to send fraudulent information requests.

Because the messages came from an official-looking mailbox that passed standard authentication checks,

Revolut treated them as legitimate legal demands and released customer files.

Affected records included names, dates of birth, addresses, phone numbers, copies of passports and driving licences, verification photos, account statements, IBANs and transaction histories, including cryptocurrency activity in some cases.

Revolut has described the number of customers as limited; later reporting put the figure near 680 to 700 people, with targets reportedly selected in part because of significant crypto holdings.

The Fintech firm says its platforms and customer funds were not compromised.

After detecting the scheme, it blocked the address, notified the relevant agency, law enforcement and regulators, and contacted the customers involved.

The aftermath has not closed quickly.

Threat actors claiming responsibility have said they used a compromised Italian official email channel over several months while posing as law enforcement.

An extortion site and ransom-style demands have circulated, including threats to sell the files if payment is not made.

Revolut has said it had not received a direct demand from the group even as public pressure mounted.

For a Fintech focused company racing toward new licenses and a possible listing, the incident is a reminder that trust in official channels can be as fragile as any technical control—and that cleaning up after a successful impersonation can last well beyond the first disclosure.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend