Revolut Hackers claim 680 ‘Crypto Whales’ targeted

By Gemma Rolfe Daily news
views

Hackers claiming responsibility for Revolut’s recent data breach say they deliberately targeted 680 customers with significant cryptocurrency holdings, adding a troubling new dimension to an incident already under investigation by regulators.

Envato Image - Licensed

Revolut Hackers claim 680 ‘Crypto Whales’ targeted

The group told the Financial Times that it used blockchain analysis to identify high-value crypto customers before impersonating Italian law-enforcement officials and requesting confidential information from Revolut.

The attackers claim they obtained addresses, telephone numbers, transaction histories and other sensitive information after compromising an Italian government email system and communicating with Revolut over several months.

Revolut maintains that its own systems and customer funds were not compromised.

Blockchain Transparency Becomes a Security Risk

The alleged targeting method illustrates an uncomfortable characteristic of cryptocurrency.

Public blockchains make transactions visible and traceable. While wallet addresses are pseudonymous, analytical techniques can identify concentrations of digital assets and sometimes associate blockchain activity with real-world individuals or organisations.

According to the attackers, that transparency was used to identify potential Revolut customers with substantial crypto holdings. Most of the 680 affected customers were reportedly based in Switzerland and France, with individuals across another 31 mainly European countries also involved.

If confirmed, the incident represents something more sophisticated than conventional phishing: blockchain intelligence appears to have been combined with compromised government communications to obtain the identities and financial records behind valuable crypto accounts.

A Trusted Government Channel Was Exploited

At the centre of the incident is Italy’s Posta Elettronica Certificata, or PEC, system, which provides legally recognised electronic communications and is widely used by government agencies and businesses.

Messages reviewed by the FT appeared to show customer information being exchanged with an arm of Italy’s interior ministry through the system. The attackers claim they had compromised access and posed as law-enforcement officials making legitimate enquiries.

That raises a broader challenge for banks and payment companies. Authenticating an email domain may establish where a communication originated, but not necessarily whether the person controlling the account is authorised to request sensitive customer information.

Extortion Claims Add Another Dimension

The episode has subsequently developed into an apparent extortion attempt. PYMNTS, citing Wall Street Journal reporting, says an attacker has published samples of customer information and threatened further disclosures unless Revolut pays. Revolut said it had informed law enforcement but declined to discuss the reported threat.

Britain’s Information Commissioner’s Office is investigating after Revolut reported the breach.

Crypto Wealth Creates a New Threat Model

The wider payments lesson extends beyond Revolut.

As banks and fintechs integrate cryptocurrency, stablecoins and traditional accounts, they increasingly hold information capable of linking pseudonymous blockchain activity to verified identities, addresses and conventional financial records.

That combination is exceptionally valuable to criminals.

The Revolut incident therefore illustrates an emerging security problem: blockchain transparency can help identify valuable targets, while compromised institutional trust can provide the route to their identities.

For financial institutions, protecting crypto customers increasingly requires securing not only wallets and transactions, but the processes through which sensitive information can legitimately leave the organisation.

Comments

Post comment

No comments found for this post