UK fintech company Revolut confirms hackers impersonated police to obtain whale data
UK fintech company Revolut has confirmed that someone used a legitimate government agency email domain to send fraudulent information requests, resulting in the company providing some sensitive customer data to unauthorized third parties. According to sources familiar with an internal investigation cited by the Financial Times, approximately 680 customers have been notified, although the company has not publicly confirmed the number. The targets were primarily high-net-worth accounts related to cryptocurrency assets. The UK Information Commissioner's Office has opened a case following the company's voluntary report. Revolut stated that its systems were not breached, and upon discovery, it immediately blocked the address and notified the relevant government agency, law enforcement, data protection, and financial regulatory bodies, with no customer funds being affected.
Italian media reported that the request came from a stolen certified email of the Reggio Calabria provincial government, and was sent under the name of the postal police; there are also materials pointing to the Ministry of the Interior domain. The company did not specify the exact agency. The information provided included identity and occupation, address, phone number, email, copies of passports and driver's licenses, registered facial verification selfies, international bank account numbers, statements, withdrawal and transaction records (including Bitcoin). The attackers claimed via Telegram that their operation lasted about five to six months and showcased what they claimed to be 147 gigabytes of Italian materials; the ransom amount circulated but was not confirmed by the company.
Publicly named victims include Mark Karpeles, former CEO of the now-defunct exchange Mt. Gox, and entrepreneur Felix Romer. The latter stated that he received a ransom demand based on the stolen data two months before the company issued its notification. On-chain investigators also revealed that passport selfies and Bitcoin transaction records were handed over. With approximately 75 million accounts in Europe, the company emphasized that the affected number is "limited." Italian postal police have reportedly opened a case regarding illegal access and telecom fraud.
The vulnerability lies in the legitimate evidence collection process, not in the production database. Domain authentication was passed, and internally viewed as European cooperation. The licensed entity in Lithuania, Revolut Bank UAB, was mistakenly identified as the target for data requests. There is no patch to apply, only a change in verification: certified email no longer equals real police.
In market mechanisms, the buyer is the attacker seeking passports and on-chain transaction records for ransom or resale, while the seller must respond to cooperation requests from licensed institutions. This is process-driven: a one-time authenticated government email turns a compliance channel into a delivery point. Data flows from the bank's compliance desk to the ransom market; the beneficiaries are the gangs that have controlled government emails, while the pressured parties are the named cryptocurrency whales, Revolut, which must explain to the authorities, and the Italian agency whose certified email was misused.
Source: Public information
ABAB AI Insight
Revolut was not "breached"; it was "worked around". The evidence collection window is a legal obligation of licensed banks, and the attackers are buying that obligation itself. Italian certified emails have presumed validity in the country, and cross-border fintech is released based on domain signatures, effectively turning the provincial government email into a European passport photocopier. The 680 individuals are not a full leak; they were manually delivered after filtering for "crypto whales", resulting in a higher damage density than credential stuffing.
The capital path is the reverse monetization of compliance costs. Banks maintain anti-money laundering and cooperation teams to stay licensed; the same team handed over selfies and Bitcoin transaction records of Mt. Gox alumni to impersonated police. If the ransom demands thousands of Bitcoins, it aims for the news price rather than the transaction price. The Information Commissioner opening a case changes the event from a public relations issue to an expectation of fines. If Italian authorities confirm the email breach, the next fine will be issued to the government side.
This is not ordinary phishing but akin to the 2016 Bangladesh central bank fake SWIFT instructions: the message format is correct, the channel is legitimate, and human review fails. The industry has shifted from preventing intrusions to preventing "legitimate requests". The position is in the control vacuum: whoever controls the government email holds the right to access licensed institutions.
Structural judgment pertains to the transfer of pricing power after the regulatory channel has been misused. The mechanism is: the more automated the cooperation, the more the domain resembles a master key. Crypto customers store their identity and on-chain history in the same account; once the key is opened, both items move together.
ABAB News · Cognitive Law
- The system was not breached; the obligation channel can also send out files.
- Once the government email passes authentication, fake police have real evidence collection rights.
- The passports and on-chain transaction volumes of whales share the same lock.