Revolut customers hit by major data breach as passport copies and transactions exposed

Date:

Revolut is reportedly facing a $3m (£2.2m) ransom demand after hackers posing as government officials gained access to the personal data of hundreds of the bank’s cryptocurrency customers, including one victim who says he is now concerned for his safety.

Europe’s largest fintech company confirmed last weekend that it had fallen victim to an impersonation scam in which hackers compromised an Italian government email system and used it to contact Revolut employees and request sensitive customer information.

The breach affected around 680 of Revolut’s 80 million customers worldwide, with the attackers reportedly targeting people believed to hold cryptocurrency.

“The data breach has reportedly impacted about 680 of Revolut’s customers, targeting those with suspected cryptocurrency holdings. Photograph: Corey Rudy/Reuters” (The Guardian)

It remains unclear whether the incident could affect Revolut’s highly anticipated stock market debut. Founder and CEO Nik Storonsky told Les Echos on Thursday that the company was planning a dual listing in London and New York.

According to the Financial Times, which has spoken to the alleged hacker, one of the individuals behind the breach has threatened to release the stolen customer data unless Revolut pays a $3m ransom. A Revolut spokesperson said the company “has not received any direct contact or demand from the individuals or group making these claims.”

However, some victims say they are now worried that they could face ransom demands themselves.

Crypto figure fears for his family’s safety

Mark Karpelès, the former chief executive of the collapsed bitcoin exchange Mt. Gox, said he was among those affected by the breach and is now concerned about the safety of his family.

“I have kids, we’re living together. My address is in those files, so of course I’m worried about this,” he told the Guardian.

Karpelès has since contacted law enforcement in Tokyo, where he lives. Earlier this week, he wrote on X that he feared he could be “kidnapped or dead” before Revolut provided him with more detailed information about the breach.

He said he was reassured that Japanese authorities were taking the threat seriously, although he remained concerned about travelling abroad or being in places where he might be less safe.

The French businessman, who has been a Revolut customer since 2023, believes the hackers may have mistakenly targeted his account because they thought he was wealthier than he actually is. Karpelès was forced into bankruptcy following a high-profile legal case in Japan.

Karpelès remains a controversial figure in the cryptocurrency world. He was charged with embezzlement following the collapse of Mt. Gox in 2014 but was later acquitted of that charge. He was convicted of falsifying financial records.

Following the Revolut breach, Karpelès joined a victim group on X where affected customers have been sharing information and supporting one another.

“We’re all in the same situation, which is: we don’t know exactly what happened, or how it happened, so we’re trying to get as much information as possible,” he said.

Karpelès also said that one victim had contacted the alleged hacker, who demonstrated that they possessed the victim’s personal information.

The hacker reportedly offered to delete the data in exchange for $50,000, according to Karpelès.

Victim warns against paying ransom

Despite his frustration with Revolut, which was valued at $115bn in a secondary share sale earlier this summer, Karpelès does not believe the company should pay the reported $3m ransom.

He argued that paying would not guarantee the stolen information would actually be deleted.

It is also unclear how many hackers are involved. The ransom was reportedly requested through Monero, a cryptocurrency designed to provide greater privacy and anonymity, meaning there would be no clear record proving that the payment had been received.

Karpelès said he hopes Revolut will provide customers with more information about what happened.

“This is very, very damaging [for the Revolut brand] because I do believe a lot of Revolut customers are more likely to be privacy sensitive,” he said, noting that privacy is often a particularly important concern among cryptocurrency investors.

Revolut says systems and funds are safe

A Revolut spokesperson said the company had identified a “sophisticated external impersonation scam” in which an unauthorised third party used the email domain of a legitimate government agency to submit fraudulent requests for information.

The company said it immediately blocked the address and notified the relevant government agency, law enforcement authorities, data protection authorities and financial regulators.

Revolut stressed that its systems and customer funds were not affected and said it had contacted the limited number of customers whose information was compromised to notify them and provide support.

Sources: The Guardian

Also read: What does the Trump–Denmark agreement on Greenland include?

Share post:

Popular

More like this
Related

Paralimni: Vehicle hits two pedestrians and flees scene – 29-year-old in critical condition

Two pedestrians were injured in a road collision in...

DISY: Turbulence comes to the fore

Internal tensions within DISY have once again come to...

From pills and injections to implants – Which innovative treatments have been approved in the past 24 months

A tiny implant is placed in the eye, gradually...

Cyprus issue takes centre stage in New York: President to meet Guterres and Holguín

New York will move to the centre of global...