top of page
Caută

Revolut had a bad week

Poza scriitorului: Office Bucuresti
Office Bucuresti
17 sept.
2 min de citit

Actualizată în: acum 1 zi

Revolut had a bad week

On September 12 they confirmed a data breach — not because someone hacked their systems, but because someone emailed them pretending to be a government agency, and it worked. The message came from an email address tied to a real government domain, asking for customer information. Revolut's team handed it over.


About 680 customer files went out the door globally. Romanian outlets reported that 27 of those were Romanian customers, which is worth noting since Revolut has close to 4.8 million retail users here — this isn't some far-away story. What got exposed: passports, driving licenses, verification selfies, home addresses, phone numbers, dates of birth, full account statements and transaction history, including crypto activity.


That last part matters more than it sounds. According to crypto investigators looking into the case, the attackers allegedly ran blockchain analysis beforehand to figure out which customers held serious crypto, then went after their identity data specifically. Someone using the handle "iamnotavillain" is allegedly demanding $3 million in Monero, though Revolut says they haven't personally been contacted with a ransom demand.


Here's the part that should worry people beyond Revolut's customer base: combine someone's real home address with proof they're sitting on crypto, and you've built a target for actual physical crime, not just fraud. It's a known pattern in the crypto world, sometimes called a "wrench attack" — data like this gets used to find and rob people in person.


No malware. No exploited software bug. Nothing technically clever. Just a convincing enough email and no hard verification step for "urgent" requests claiming to be from a government authority.


If someone emailed your organization tomorrow claiming to be law enforcement and asking for customer records, would there be a mandatory second check before anyone replied — a callback to a verified number, a formal channel — or would it come down to whether the email looked right? Worth finding out before you have to.


Sources: TechCrunch, Help Net Security, Cryptopolitan, Cotidianul.ro, Forbes.ro


Originally published on the IPSTSO LinkedIn page on 17 September 2026: view the post

 
 
 

Comentarii


Nu se mai pot adăuga comentarii la această postare. Contactează proprietarul site-ului pentru mai multe informații.
bottom of page
Sigla IPSTSOIPSTSOINTERNATIONAL POLICE SECURITY TECHNOLOGY SYSTEM ORGANIZATIONDEPUNE O SESIZARE