FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.6T -1.5%24h Vol $12112304.1T +13297434235%Fear & Greed 69/100Alts Index 29/100
BTC.D 58.3% -0.3%Stable.D 10.0% +0.1%ETH.D 11.2% -0.3%Others.D 20.5% +0.5%
AKE$0.0273+78.56%AI$0.3214+35.32%龙虾$0.1779+19.42%ARC$0.0812+13.87%牛来$0.1189+11.99%FF$0.1407+10.66%LAPTOP$0.2390+9.71%CAP$0.0603+2.49%NFT$0.00000024+2.4%JST$0.1147+1.51%
UAI$0.3767-28.04%LSK$0.3404-19.78%SENT$0.0143-17.7%B$0.1990-17.24%FIL$0.8191-15.07%INJ$5.478-14.31%RAY$1.210-13.44%SPX$0.4564-12.19%AR$2.477-12.15%RAIN$0.0132-12.14%
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      Revolut’s Breach Toll Emerges as the ICO Opens a Probe

      Revolut has contacted 680 customers whose personal and financial data was handed to an unauthorized party after staff processed a fraudulent information request sent from a legitimate government email domain, the Financial Times reportedThe ICO has opened an investigation into the incident, which Revolut reported to the watchdog.

      How a Government Email Bypassed Revolut's Controls

      The attack did not involve a system intrusion. An unauthorized party used a real government agency's email account with valid domain-authentication credentials to submit what appeared to be a standard compliance request for customer records, IBTimes UK reportedThe emails passed technical checks, and Revolut staff processed them as legitimate. Material circulated through a since-suspended Telegram account suggested the email originated from an Italian government domain, though that detail remains unverified.Revolut stated that its systems and customer funds were unaffected and that it "blocked the email address after discovering the scam. The firm notified the relevant government agency, law enforcement, and relevant regulators, according to its public statement.

      Passport Scans, Selfies, and Bitcoin History Cannot Be Rotated

      The exposed categories set this breach apart from a typical email-and-password leak. Compromised records included names, dates of birth, postal and email addresses, phone numbers, copies of passports and driving licences, account verification selfies, IBANs, full account statements and withdrawal records, and complete Bitcoin transaction histories, according to the Financial Times and Help Net Security.Critically, private keys, passwords, and full payment-card numbers were not among the exposed data. The problem for affected customers is that passwords can be changed and cards can be cancelled, but a passport scan or a verification selfie cannot be "rotated" the way a credential can. ESET Ireland warned that criminals could use the stolen identity documents to impersonate Revolut staff or other entities, open fraudulent accounts, or commit further identity fraud. The cybersecurity firm advised affected customers to check their records with Ireland's Central Credit Register and to consider replacing their identity documents, TheJournal.ie reported.

      The ICO Will Examine Revolut's Safeguards

      Under its published guidance, the ICO typically weighs the type of data exposed, the number of people affected, potential harm and the safeguards in place before deciding on regulatory action.Around 12 of the affected customers are based in Ireland, raising the possibility that Ireland's Data Protection Commission could open a parallel inquiry. Among the 680 was Mark Karpeles, the former chief executive of Mt. Gox, who was notified by Revolut on September 12.Karpeles told the Financial Times that he believes Revolut should not have shared the information regardless of whether the email came from a verified government address.

      Extortion Claims and the Lesson for Exchanges

      Individuals claiming responsibility for the attack have threatened to publish the stolen data unless Revolut pays a ransom. Revolut has not confirmed whether ransom discussions took place, and the extortion claims remain unverified.For FinanceFeeds' broker and exchange readership, the incident carries a specific operational lesson. Revolut's controls trusted a technically authenticated email from a government domain without requiring a second verification channel. George Foley, a cybersecurity specialist quoted by TheJournal.ie, warned affected customers that "Revolut, or any other bank or state agency, will not ask customers to move money" and urged vigilance against follow-on scam messages.The 680 figure may not be final; the ICO investigation and any regulatory action from the Bank of Lithuania, Revolut's banking-licence regulator, could shape the regulatory fallout.

      Source: FinanceFeeds
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud