Revolut, Europe’s largest financial technology firm, has revealed that it was targeted in a sophisticated impersonation scam involving hackers who accessed personal data belonging to nearly 700 of its customers, primarily those with suspected cryptocurrency holdings. The incident came to light last weekend and has escalated with reports that the attackers are demanding a $3 million ransom to prevent the release or sale of the stolen information.
The breach occurred after hackers compromised an Italian government email system, which they used to send fraudulent requests for customer details to Revolut staff. The company confirmed it identified the scam quickly, blocked the malicious email address, and notified relevant government, enforcement, data protection, and financial regulatory authorities. Revolut emphasized that its systems and customer funds remain secure and unaffected by the incident.
While the breach affected roughly 680 accounts out of Revolut’s global customer base of 80 million, it is significant given Revolut’s high profile in the fintech sector and its recent receipt of a full banking license from the Bank of England in March. The process to secure the license took more than five years, partly due to the company’s scale and the heightened regulatory scrutiny it faced. The hack raises questions about internal controls as well as data security, especially given Revolut’s plans for a stock market debut with potential dual listings in London and New York.
Among those impacted is Mark Karpelès, the former chief executive of the collapsed bitcoin exchange Mt. Gox. Karpelès, who has been a Revolut customer since 2023, expressed concern for his family’s safety, noting that sensitive information such as his home address was included in the compromised data. He has engaged with law enforcement in Tokyo and joined a victim support group online as he awaits further details from Revolut. Karpelès stated that the hackers may have mistakenly targeted him, believing he held greater wealth than he does. Despite frustration with Revolut, he advised against paying the ransom, citing uncertainties about whether the data would be deleted after payment.
One individual reportedly contacted the hacker, who demanded $50,000 to delete their personal data. The broader ransom demand of $3 million is said to be requested in the cryptocurrency Monero, a medium that would obscure payment trails and complicate verification that funds were received.
Revolut maintains that it has not received any direct communication or ransom demand from the hackers, despite the public assertions. The company has contacted those affected to inform them and provide support.
The breach is seen as potentially damaging to Revolut’s reputation, particularly among cryptocurrency investors, who often prioritize privacy and data security. Stakeholders and regulators are expected to review the incident closely as Revolut continues to expand its banking services and prepares for its forthcoming market listing.
