Loading prices…
🩸BEARISH

Revolut Data Breach Leaks 680 Customers' Bitcoin Records

The exposed files include passport details, home addresses and Bitcoin activity, and the attackers are now threatening publication unless a ransom is paid, with the UK ICO opening an investigation.

Revolut Data Breach Leaks 680 Customers' Bitcoin Records
Revolut Data Breach Leaks 680 Customers' Bitcoin Records

Revolut disclosed sensitive data on 680 customers after cybercriminals used a legitimate government email account to submit fraudulent information requests, the Financial Times reported. Exposed records included passport details, bank account numbers, home addresses, identity-verification images and Bitcoin activity, and the attackers are threatening to publish the data unless a ransom is paid.

The International Cyber Digest, which contacted the hacker claiming responsibility, reports the operation ran for roughly six months and exploited compromised Italian law-enforcement systems to send the fraudulent requests. The attacker says the stolen records primarily involve customers in Switzerland and France, alongside users in the UK, Germany, Italy and other countries, including several high-profile individuals. Former Mt. Gox CEO Mark Karpelès was among those affected.

Why it matters

The breach shows how social-engineering attacks on the KYC layer bypass technical controls entirely: attackers did not hack Revolut's systems, they impersonated the state. For a fintech holding identity documents and Bitcoin activity records on millions of users, the extortion threat turns compliance data into direct attack surface.

Market impact

The UK Information Commissioner's Office has opened an investigation, and Revolut says it blocked the email account and notified regulators and affected customers. The reputational and regulatory cost for Revolut's UK banking-license ambitions is the number to watch, alongside whether other exchanges and fintechs audit how they verify government data requests.

Related tokens
$BTC

Frequently asked questions

  1. How did hackers get customer data from Revolut?

    They used a legitimate government email account to submit fraudulent information requests, exploiting Revolut's compliance process rather than hacking its systems. The attacker claims the scheme ran for about six months using compromised Italian law-enforcement systems.

  2. What data was exposed in the Revolut breach?

    Records on 680 customers included passport details, bank account numbers, home addresses, identity-verification images and Bitcoin activity. The attackers are threatening to publish the data unless a ransom is paid.

  3. Which countries' Revolut customers were affected?

    The attacker says the records primarily involve customers in Switzerland and France, alongside users in the UK, Germany, Italy and other countries, including several high-profile individuals.

  4. Is Revolut under investigation for the breach?

    The UK Information Commissioner's Office has opened an investigation. Revolut says it blocked the fraudulent email account and notified both regulators and affected customers.

  5. Were any well-known individuals affected by the Revolut leak?

    Yes. Mark Karpelès, the former CEO of the collapsed Mt. Gox Bitcoin exchange, was among the affected customers, per the disclosure reported by the Financial Times.

Source attribution
Aggregated from WuBlockchain · Verified · Last refreshed 50m ago
Open original →