Revolut Hacked: Attackers Impersonate Police to Steal Crypto Whale Data
UK fintech company Revolut has fallen victim to a sophisticated hacking operation that saw attackers impersonate law enforcement agencies to obtain sensitive customer data. The company confirmed that hackers used a legitimate government email domain to send fraudulent information requests, resulting in the provision of customer data to unauthorized third parties.
The affected customers were primarily high-net-worth individuals with cryptocurrency assets, with approximately 680 notified by Revolut. The targets included former Mt. Gox CEO Mark Karpeles and entrepreneur Felix Romer, who received a ransom demand based on stolen data two months before the company issued its notification.
Revolut stated that its systems were not breached, and it immediately blocked the malicious address and notified relevant authorities upon discovery. The company emphasized that no customer funds were affected by the incident, which is now being investigated by the UK Information Commissioner's Office.
The vulnerability in this case lies in the legitimate evidence collection process, where domain authentication was mistaken for real police verification. Revolut has since changed its verification processes to prevent such incidents in the future.