Revolut Accused of Supplying Hacker‑Stolen Data to Impersonators for Five Months
Fintech firm Revolut is under scrutiny after allegations surfaced that the company allegedly supplied customer data to cyber‑criminals posing as an Italian government agency for a period of five months. The breach reportedly involved 680 accounts linked to high‑profile individuals and culminated in a ransom demand of roughly $3 million.
According to the initial report published by SecurityWeek, the attackers used the stolen information to craft convincing phishing messages that appeared to originate from the Italian authority, prompting victims to disclose further credentials. Over the course of the operation, the compromised data set was allegedly passed from Revolut to the fraudsters, enabling them to target a select group of users with significant financial and personal assets.
Revolut, which has positioned itself as a secure, border‑less banking alternative, has not yet issued a detailed public statement addressing the specific accusations. The company’s standard security policies emphasize encryption, two‑factor authentication, and continuous monitoring, but the alleged incident raises questions about internal data handling practices and third‑party vetting procedures.
Regulators in the United Kingdom and the European Union are expected to examine the case closely, given the cross‑border nature of the alleged fraud and the potential breach of GDPR provisions. Data protection authorities typically assess whether firms have implemented adequate safeguards and whether they responded promptly to signs of compromise. Failure to meet these standards can result in substantial fines and mandatory remediation measures.
Industry analysts note that the incident, if verified, underscores the growing sophistication of social engineering attacks that blend technical exploitation with impersonation of trusted institutions. Cyber‑security experts warn that the use of a government façade can dramatically increase victim compliance, especially when the targeted individuals hold public or corporate prominence.
Revolut’s next steps may include commissioning an independent forensic audit, notifying affected customers, and cooperating with law‑enforcement agencies to trace the flow of the alleged $3 million ransom. The outcome of any investigations will likely shape the company’s reputation and could influence broader discussions about data stewardship responsibilities within the rapidly expanding fintech sector.
Comments (0)
Be the first to comment.
Join the discussion