Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Revolut Denies Direct Ransom Contact Following Data Breach of 680 European Customers

Revolut denied receiving direct contact or ransom demands after hackers stole data from approximately 680 high-net-worth European customers through social engineering attacks impersonating government authorities.
6 hours ago 21 views
Revolut Denies Direct Ransom Contact Following Data Breach of 680 European Customers

Revolut stated it has not received direct contact from or demands by any group claiming responsibility for a recent data breach affecting roughly 680 high-net-worth customers across Europe. The denial came after reports that hackers demanded 6,000 XMR, valued at approximately $3 million, in exchange for not releasing the stolen data.

The London-based fintech company confirmed that an unauthorized third party obtained sensitive customer information by using a legitimate government agency's email domain to submit fraudulent data requests. Hackers operating under the online handle "IAmNotAVillain" publicly threatened to release or sell customer data unless Revolut paid the ransom.

According to Revolut, the attackers used social engineering over several months to impersonate government authorities, obtaining customer verification files, identity documents, and transaction records. The breach did not involve a direct technical intrusion into Revolut's core systems. The company stated that customer funds and internal systems remain secure and unaffected, and it blocked the fraudulent email address upon discovering the incident.

Revolut reported the breach to law enforcement, data protection authorities, and financial regulators.

KYC Requirements Create Security Vulnerabilities, Analyst Warns

Jonathan Riss, an open-source and blockchain intelligence analyst at security firm Certik, argued that the incident highlights broader systemic vulnerabilities extending beyond individual companies' defenses to regulatory requirements themselves.

Riss stated that mandatory know-your-customer (KYC) rules require financial platforms to maintain an extremely sensitive identity data layer, often because governments and regulators demand increasingly detailed customer information. He contended that responsibility for data security does not rest solely with banks, fintechs, or cryptocurrency exchanges.

According to Riss, public authorities should reconsider whether every piece of information they require is genuinely necessary and how long it should be retained. They should also evaluate whether existing procedures for requesting customer data are sufficiently secure.

Riss noted that platforms should minimize data retention, restrict access, and strengthen authentication of government and law enforcement requests through independent verification channels. He suggested the incident should prompt the industry and regulators to rethink the current model to protect users' financial identities alongside protecting wallets and funds.

Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.