Cryptographic Data Breach: Revolut in Hot Water Following Social Engineering Attack
In a troubling incident within the realm of digital finance, Revolut, a popular payments platform known for its cryptocurrency services, fell victim to a sophisticated social engineering attack. Cybercriminals managed to access sensitive information pertaining to numerous high-risk individuals by exploiting a compromised email account belonging to a legitimate government agency. This breach not only raises alarms about data security protocols within financial institutions but also brings to light the personal safety risks faced by the victims.
According to mathew J. Schwartz, the hacker involved in this breach is believed to have stolen personally identifiable information (PII) from a select group of customers. This prompted Revolut to issue warnings regarding the potential personal safety threats faced by those impacted. After notifying affected customers on September 10, 2026, the company publicly confirmed its susceptibility to the attack, detailing that the data acquisition was achieved through manipulated requests issued via an authentic government email account that had been compromised.
Kela, a threat intelligence firm, provided insights into the breach. They pointed out that fraudsters had artfully crafted requests for customer data using a government email domain, which successfully passed Revolut’s technical authentication measures—namely SPF, DKIM, and DMARC protocols. Unbeknownst to Revolut’s compliance and legal team, these deceptive mandates were interpreted as genuine official orders, leading them to release sensitive files pertaining to a limited number of users.
Founded in 2015 and based in London, Revolut operates banking services across 30 countries, offering features such as digital banking, multi-currency accounts, and cryptocurrency exchanges through its mobile application. Recently, the company announced a customer base exceeding 80 million globally while contemplating an initial public offering (IPO) in the upcoming year that could value the venture at approximately $200 billion.
Importantly, Revolut clarified that no customer funds were stolen and that the threat actor did not gain unauthorized access to the company’s systems. However, the types of sensitive data that were compromised included customer names, contact information, bank account details, cryptocurrency wallet information, transaction histories, and copies of identity verification documents used during the Know Your Customer (KYC) process—this encompasses items like driver’s licenses, passports, and even personal selfies.
Reports suggest that the total number of victims stands at about 680 customers, as indicated by the Financial Times. The hacker, identified as "IAmNotAVillain," showcased evidence of their nefarious activities, reportedly possessing approximately 326 megabytes of data and around 688 files linked to the breach.
The data theft campaign reportedly spanned six months, beginning when the hacker gained access to a system utilized by Italian federal agents, installing a remote-access Trojan to facilitate their infiltration. Utilizing this access, the hacker mentioned that they engineered a scenario to persuade Revolut into divulging sensitive information, even extending beyond Italian customers.
Among the high-profile individuals affected by this breach is French businessman Mark Karpelès, the former CEO of the now-defunct Mt. Gox bitcoin exchange, who confirmed receipt of Revolut’s breach notification. Other notable cryptocurrency figures, including entrepreneur Marc Zeller, voiced their concerns following the breach, noting that the event highlights serious flaws in the KYC processes and raises significant personal safety concerns. Zeller pointed out that such practices could inadvertently place individuals at greater risk.
Felix Romer, founder of the online crypto gambling platform Gamdom, took to social media to express his dissatisfaction, asserting that he and others began receiving blackmail attempts using the compromised data months prior to Revolut’s public acknowledgement of the breach. He shared a screenshot of an extortion message that had surfaced as early as July.
The breach has not only instigated anxiety surrounding the risk of personal data exposure but also prompted unwelcome attention from cybercriminals. Investigators like ZachXBT highlighted that the focus of the attack seemed particularly targeted at high-net-worth individuals, amplifying fears surrounding potential extortion attempts.
Both "IAmNotAVillain" and another hacker, known as "Revolut Smilik," have claimed responsibility for the breach, detailing their actions in Telegram channels. "IAmNotAVillain" distanced themselves from an alleged impersonator, asserting their authenticity and cautioning victims against negotiating with anyone else.
The hacker disclosed to online news sources that the majority of the stolen data belonged to Revolut customers in France and Switzerland, although they claimed to possess information from customers across various nations, including nearly the entire European Union, along with Norway, Turkey, the United Kingdom, and the Bahamas.
In a chilling move, the hacker established a clearnet data-leak site to promote the stolen data, indicating that it included sensitive transactions as well as KYC documents. This website was reportedly taken offline shortly after launching, emphasizing the speed at which these breaches unfold and the paramount necessity for robust security protocols in the digital financial sphere.
The implications of this breach extend far beyond the technical failures that facilitated it. They underscore an urgent need for enhanced cybersecurity measures within institutions that handle sensitive financial data. The lives of those affected hang in the balance, with the threat of serious personal repercussions looming large in the aftermath of this incident.
