Revolut Faces a $780M Ransom Over a Breach Without a Hack

fiverr
Coinmama


  • Attackers reportedly demand 10,000 BTC, worth about $780 million.
  • Revolut confirms customer data was disclosed, but says systems and funds remain secure.
  • Exposed records may include identity documents and Bitcoin transaction histories.
  • The incident exploited government-request verification rather than Revolut’s core systems.

Attackers linked to Revolut’s customer data exposure are reportedly demanding 10,000 BTC, worth roughly $780 million, after beginning to publish information allegedly belonging to high-profile clients. Revolut has confirmed the underlying disclosure but has not verified the ransom demand or authenticated the material being released by the threat actors.

Attackers Put a $780 Million Price on the Stolen Data

The extortion attempt emerged after the group claiming responsibility began publishing records it says belong to Revolut customers and threatening further releases.

According to Yahoo Finance, the attackers are reportedly demanding 10,000 BTC and have threatened to publish additional customer information each day until payment is made. The ransom figure remains an attacker claim rather than a confirmed demand acknowledged by Revolut or law enforcement.

The group has also accused Revolut of negligence in protecting customer privacy and alleged that sensitive information was supplied to countries outside appropriate jurisdictions. Those allegations have not been independently established.

Binance

What is confirmed is the earlier disclosure that gave an unauthorized party access to unusually sensitive financial and identity information.

An Authentication Scam, Not a Core System Breach

Revolut says the incident began when an unauthorized party submitted fraudulent information requests using an email account operating from a legitimate government agency domain.

The requests appeared authentic, leading Revolut to provide customer information before discovering the deception. The company has characterized the incident as a sophisticated external impersonation scam rather than an intrusion into its banking infrastructure.

After identifying the unauthorized request, Revolut blocked the email address and notified the government agency involved, law enforcement, data protection authorities and financial regulators.

The company has not identified the agency or disclosed an exact number of affected customers, describing the group as limited. Revolut also said its systems and customer funds were unaffected.

The control failure sits in the process used to authorize disclosure of financial records. A request can originate from authentic government infrastructure without proving that the individual behind it has authority to obtain a particular customer’s information.

That means financial institutions handling government demands need to verify more than the sender’s technical credentials. The requesting official, jurisdiction, legal basis and scope of the information sought are separate controls.

Why KYC Plus Bitcoin History Heightens Risk

The potential data exposure extends considerably beyond contact information.

According to notices sent to affected customers, records may include names, dates of birth, occupations, postal addresses, email addresses, telephone numbers and copies of passports or driver’s licenses. Verification selfies may also have been disclosed.

Financial records potentially include account statements, IBANs, withdrawal information and complete transaction histories, including Bitcoin activity. Revolut said biometric facial telemetry was not compromised, distinguishing the underlying verification image from biometric data derived from it.

Former Mt. Gox CEO Mark Karpelès said publicly that he was among the affected customers and shared material from the notification he received.

Onchain investigator ZachXBT, who helped bring wider attention to the incident, said the exposure appeared limited in size but seemed to have targeted high-net-worth users. Revolut has not confirmed that assessment.

The combination of identity and financial records creates a particular problem for crypto holders.

Bitcoin transactions are publicly observable, but blockchain addresses do not inherently disclose the legal identity or residential address of the person behind them. Records connecting transaction histories with passports, names and physical addresses can remove part of that separation.

For an attacker, the resulting dataset can also make impersonation significantly more convincing. A fraudulent caller who already knows a victim’s identity, banking information and previous transactions can construct a highly personalized approach without needing access to the victim’s Revolut account.

The Broader Industry Failure

The longer-term issue now extends beyond the ransom attempt.

Financial institutions routinely process requests from law enforcement agencies, regulators and other government authorities. The Revolut incident demonstrates the weakness that emerges when a trusted communication channel becomes part of the attack itself.

That is particularly relevant because conventional email security controls are designed primarily to establish whether a message originates from authorized infrastructure. Revolut’s customer notice indicated that the fraudulent request came from within the real government domain and carried genuine authentication credentials.

The next meaningful disclosure will therefore be what Revolut changes in its government-request verification process.

Secondary confirmation with the requesting authority, independent validation of the official making the request and tighter jurisdictional checks could become more important when a demand involves passports, residential addresses and complete financial histories.

For other banks, exchanges and fintech companies, the incident also raises a practical question: whether requests previously received from the same government infrastructure should be reviewed once the affected agency is identified.

That could ultimately determine whether Revolut encountered an isolated fraudulent request or exposed a method capable of being used against other financial institutions.

Actionable Steps for Affected Revolut Users

  • Verify contacts in-app: Never trust phone numbers, contact details or links contained in unexpected messages. Confirm unusual requests directly through the official Revolut app.
  • Protect authentication credentials: Never provide passwords, authentication codes or wallet seed phrases in response to unsolicited contact. Genuine personal information in a message does not make the sender legitimate.
  • Beware of personalized scam attempts: A caller who knows your address, banking details or previous Bitcoin transactions is not automatically verified as Revolut or law enforcement. The exposed information itself can be used to make impersonation attempts appear credible.

Source: https://www.crypto-news-flash.com/revolut-faces-a-780m-ransom-over-a-breach-without-a-hack/





Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*