FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.6T +0.1%24h Vol $104.6B -0.8%Fear & Greed 51/100Alts Index 27/100
BTC.D 58.6% 0%Stable.D 10.2% 0%ETH.D 11.3% 0%Others.D 19.9% 0%
LSK$0.6738+96.34%AKE$0.0273+78.56%AI$0.3214+35.32%ARB$0.1650+20.45%龙虾$0.1779+19.42%USELESS$0.2355+16.14%牛来$0.1189+11.99%MARSCOIN$0.0985+10.75%LAPTOP$0.2390+9.71%ZEC$1,227.41+8.62%
UAI$0.3767-28.04%RAIN$0.0132-12.14%PI$0.0837-12.02%XCN$0.00392159-10.58%CAP$0.0579-9.46%XLM$0.1763-8.99%INJ$5.396-8.88%STX$0.2380-7.96%PONS$0.5877-7.96%JTO$0.4075-7.54%
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      Researchers Uncovered Scheme Involving Fake Crypto Requests on Revolut

      • Analysts uncovered how Revolut shared customer data via fake requests.
      • At the center of the incident was not a hack of the banking app itself, but abuse of the channel through which financial institutions interact with government agencies.
      • 680 Revolut customers may have been affected by the leak.
      • According to researchers, the attackers used public crypto transactions and wallet addresses to obtain KYC data on potentially wealthy users.

      Fintech company Revolut faced the fallout from a data leak affecting around 680 customers after attackers used compromised Italian government email inboxes to send fake requests to the fintech firm. This was reported by FT and International Cyber Digest.

      Amid the publication of user data and possible ransom demands, researchers are detailing the attack mechanism, while lawyers and civil rights advocates point to a systemic problem with verifying government requests in the financial sector.

      In addition, some of the claims are being spread by the alleged attackers themselves. Revolut has not confirmed all of the published figures and details.

      According to early Revolut investor and independent analyst Max Karpis, the company received ransom demands, and people claiming to possess the stolen files began posting copies of customer documents and selfies on Telegram. 

      At the same time, Karpis stressed that Revolut has not yet confirmed the claimed amount of 10,000 BTC, and that the information should be treated with caution.

      “Revolut still says “limited,” and that the app and the money were not hacked. This is extortion after a Revolut employee handed KYC to an unauthorised mailbox on a real government domain. Paying would not put the passports back,” he wrote.

      Karpis also urged potentially affected users to take additional security measures: freeze credit lines where possible, set a new passcode and card transaction alerts in the app, and avoid engaging with people who already know the user’s IBAN or their previous cryptocurrency transactions.

      Separately, he advised considering replacing a passport, since in some countries, after a document is compromised, the old number can be canceled and a new one issued. At the same time, the expert warned about another potential scam: offers to “delete the file” for money may be an attempt to extort funds again.

      How Attackers Could Have Obtained Cryptocurrency Customer Data

      According to an X user under the handle Korra, an attacker using the alias IAmNotAVillain employed a so-called spray-and-pray tactic: sending Revolut hundreds of cryptocurrency transaction IDs and deposit addresses, and asking for information about the accounts associated with them.

      Duel claims that such requests were sent under the cover of a forged European Investigation Order — a European investigative order. Revolut allegedly responded by providing archives containing customer data.

      Researchers said they obtained and verified authentic copies of emails in .eml format. One of them contained 10 folders, each dedicated to a separate customer. According to Duel, the folders contained:

      • Photos of identity documents
      • Verification selfies
      • Account information
      • Unredacted transaction data

      According to researchers, the password to the encrypted ZIP archive was sent in a separate email.

      This scheme also explains why the attackers may have deliberately sought information about wealthy Revolut clients. Public blockchains make it possible to see addresses and transactions, meaning a crypto transaction could be used as a kind of search key for a request to a centralized financial institution.

      Researchers claim the attacker sent Revolut hundreds of transaction hashes and deposit addresses that, in their view, were linked to high-asset clients. The company then allegedly returned information about the corresponding users.

      Separate claims about 147 GB of data allegedly stolen from Italian government systems, as well as about the publication of client data, are being circulated by researchers and people who say they are in contact with the attackers. 

      Human rights advocate and Open Dialogue Foundation President Lyudmyla Kozlovska noted that new documents confirm that on July 24, 2026, Revolut refused to directly disclose information in response to a request covering 198 hashes. According to her, 169 of them were linked to Revolut Ltd in the United Kingdom, and another 29 — to the Swiss legal entity.

      Kozlovska claims the company invoked a legal ground for refusal — a jurisdictional limitation. The request concerned only accounts at Revolut Bank UAB in Lithuania, while in other cases the applicant was directed to the UK mutual legal assistance procedure.

      At the same time, she emphasized that European anti-money laundering rules do not impose a separate obligation on a bank to verify the true party behind an authenticated government request.

      “EU AML law imposes no verification duty on the bank and provides no meaningful mechanism to check who is really behind an authenticated state request. Refusal to answer carries fines in the millions,” Kozlovska said.

      What Victims Are Advised to Do, and Why the Incident Has Broader Implications

      Kozlovska urged European citizens to contact their Members of the European Parliament and demand urgent hearings on the use of mass financial data collection as a tool for attacks.

      She also pointed to a potentially broader issue: a similar risk may apply to banks, crypto exchanges, and payment services in jurisdictions where FATF rules and relevant AML legislation are in force.

      According to her, financial institutions are required to respond to properly оформлені government requests, while the mechanisms for verifying who is actually behind such a request may be limited.

      Kozlovska noted that the issue has already been raised before the European Parliament by human rights organizations, victims, and experts, with the support of the Open Dialogue Foundation. She added that this year, in a resolution dated June 18, 2026, the European Parliament separately flagged the risk of transnational financial repression.

      As of the time of writing, Revolut has not published separate recommendations on its X page regarding clients’ next steps in connection with the incident.

      As a reminder, Revolut recently received conditional approval to establish a national bank in the United States.

      Сообщение Researchers Uncovered Scheme Involving Fake Crypto Requests on Revolut появились сначала на INCRYPTED.


      Source: Incrypted
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud