Revolut breach exposes 680 customers to hackers posing as officials
Regulation & Gov ·
The neobank confirmed attackers used a hijacked government email account to extract sensitive records, and are now demanding payment to keep the data private.
Revolut has acknowledged that personal information belonging to 680 customers was handed over to criminals who impersonated a government body through a compromised official email address, according to reporting from the Financial Times as relayed by WuBlockchain. The compromised material reportedly spans passport scans, banking details, residential addresses, identity-verification photos and records of Bitcoin transactions tied to affected accounts.
Attackers have since threatened to release the stolen files publicly unless they receive a payout, a demand separately reported as a request for 10,000 BTC by CryptoPotato. The scale of that figure underscores how attackers are treating the leverage from identity documents and financial histories as a high-value bargaining chip rather than a routine extortion attempt.
The breach mechanics hinge on trust in official channels: because the request appeared to originate from a legitimate government account, Revolut's internal review processes accepted it as valid before the fraud was detected. The company has since cut off access to that email account, alerted regulators, and reached out directly to the customers whose information was exposed.
Britain's Information Commissioner's Office has opened a formal inquiry into how the disclosure occurred and what safeguards failed. Among the individuals whose data was compromised is Mark Karpelès, formerly chief executive of Mt. Gox, whose inclusion highlights that even high-profile figures within the crypto industry were not shielded from the exposure.
What remains unclear is whether Revolut or any customers will pay the ransom, how the ICO investigation will conclude, and whether additional impersonation attempts using government credentials have targeted other financial institutions. It is also not yet established how the attackers initially gained control of the government email account used to file the fraudulent requests.