Person typing on a laptop displaying green computer code in a dark room, representing cybersecurity threats and hacking.
TECHNOLOGY

Revolut Data Leak Hits 680 Customers, Crypto Records Exposed

Image credit: Shutterstock

Revolut disclosed sensitive customer records after fraudulent information requests were sent from an email address on a legitimate Italian government domain and appeared to come from law enforcement.

Around 680 customers were reportedly affected, with many holding substantial cryptocurrency assets. Revolut says its own systems were not breached, and customer funds remain secure.

Legitimate Italian Government Email Made Fraudulent Requests Appear Authentic 

The attackers claim they compromised an Italian government email account using the country’s certified Posta Elettronica Certificata, or PEC, system and used it to impersonate law enforcement.

Fraudulent requests were reportedly sent repeatedly over a period of several months. Italian authorities are investigating, but have not publicly verified the attackers’ full account of how access was obtained or how long it lasted.

Revolut has not publicly identified the government agency involved. It said it blocked the email address after detecting the impersonation and notified the affected agency, law enforcement and regulators.

Passports, Addresses, and Bitcoin Histories Were Potentially Exposed 

Customer notices show that information potentially disclosed included names, dates of birth, phone numbers, email and postal addresses, identity documents and verification selfies.

Account statements, IBANs, withdrawal records and transaction histories were also potentially exposed. For some customers, those records included Bitcoin transactions, linking sensitive identity information with crypto activity.

Reporting on the incident puts the affected population at around 680 customers across more than 30 countries, with Switzerland and France among the largest groups. Revolut has described the affected number as limited but has not publicly confirmed the total.

Attackers Threaten Further Disclosure Of Stolen Customer Records 

Combining identity documents, home addresses and crypto transaction histories creates additional security concerns because the records can reveal both personal information and financial activity.

Attackers have reportedly threatened to publish stolen customer records unless Revolut meets their demands. Revolut has not disclosed the terms of any extortion attempt.

Italian authorities are investigating the government email compromise, while Revolut has said it strengthened its controls after detecting the fraudulent requests.

More For You

Explore More News