Breaking
CNRussian drone attacks Odessa, Ukraine again, injuring at least 5 peopleITPetrol station hit near the border with PolandINTLSweden heads to polls in knife-edge general electionCNIndonesian Java Sea ferry lost contact due to bad weather, 103 people rescued, 1 dead, 140 missingTR2 Palestinians lost their lives in Israeli attacks in GazaESMadrid hosts its first Formula 1 race in 45 years with more than 100,000 attendees expectedINUkraine Expands Counter-Russia Operations to Africa and the Middle EastTRSearch continues on the loss of an 11-month-old baby in DivriğiTRThe Effect of Wars on Energy Markets and Renewable Energy InvestmentsFRA teenager indicted for rape of a minor in Toulouse, similar facts not followed upCNRussian drone attacks Odessa, Ukraine again, injuring at least 5 peopleITPetrol station hit near the border with PolandINTLSweden heads to polls in knife-edge general electionCNIndonesian Java Sea ferry lost contact due to bad weather, 103 people rescued, 1 dead, 140 missingTR2 Palestinians lost their lives in Israeli attacks in GazaESMadrid hosts its first Formula 1 race in 45 years with more than 100,000 attendees expectedINUkraine Expands Counter-Russia Operations to Africa and the Middle EastTRSearch continues on the loss of an 11-month-old baby in DivriğiTRThe Effect of Wars on Energy Markets and Renewable Energy InvestmentsFRA teenager indicted for rape of a minor in Toulouse, similar facts not followed up
NewsgatherNewsgather
All StoriesWorldSportsFinanceTechScience
Sign In
All StoriesWorldSportsFinanceTechScienceHealthCultureClimatePoliticsSpace
NewsgatherNewsgather

Real-time global news intelligence. Curated by humans, powered by data.

Sections

All StoriesWorldSportsFinanceTechScience

More

HealthCultureClimatePoliticsSpace

Company

AboutEditorial StandardsAdvertisingCareersPressContact

©️ 2026 Newsgather. A product by All Software 24. All rights reserved.

Privacy PolicyCookie PolicyImprintTerms of UseContent and Editorial PolicyRemoval RequestAdvertising PolicyContact
Back|Data leak at Revolut: social engineering attack exposes wealthy customers
Data leak at Revolut: social engineering attack exposes wealthy customers
Developing
Journal du Coin·17 minutes ago·Tech·7 min read·

Data leak at Revolut: social engineering attack exposes wealthy customers

A fraudulent email sent from a government agency's domain fooled Revolut's compliance checks, compromising passports and Bitcoin logs.

Quick Look

Between September 11 and 12, Revolut fell victim to a social engineering scam via an authenticated email from a government agency, exposing sensitive data and Bitcoin histories of wealthy customers.

AI-generated summary

Why It Matters

Social engineering involves manipulating human trust to gain access or information, thereby circumventing technical barriers.

Font size

The habit does not make the monk. No one forced a single door. No one injected any virus. Between September 11 and 12, someone simply wrote to Revolut from an address that had every appearance of legitimacy. The neobank responded as one responds to an authority that one does not dream of contradicting. Result: passports, verification selfies and Bitcoin transaction histories of wealthy clients ended up in the hands of strangers. No firewall had a say.

Revolut thought it was speaking to the State, and the State had nothing to do with it

What is social engineering?

Social engineering is the art of hacking a person rather than a machine. Instead of forcing a password or exploiting a software flaw, the attacker manipulates trust. It poses as a legitimate authority such as customer service, a bank, or even a government agency. The objective? Convince your target to provide them with the information or access they seek.

The principle has existed since before computers. But digital technology has made it formidably effective: a well-constructed email, sent at the right time from the right address, costs infinitely less than a security audit to penetrate a company's technical defenses.

Revolut, victim of access deemed legitimate

In the Revolut case, social engineering took a particularly vicious form. The attacker did not even need to imitate an address: he had real access inside the email domain of a government agency. Consequence: a fraudulent request deemed indistinguishable from a real legal requisition by Revolut’s compliance teams.

The incident comes at a particularly sensitive time for the neobank. Revolut obtained its full banking authorization in France in August 2026, a few months after that obtained in the United Kingdom. The neobank would also explore an IPO at a valuation of between 150 and 200 billion dollars according to TechCrunch, compared to 75 billion during its last private raising. A financial trajectory that this type of data leak certainly does not help to secure.

A mechanism that fooled all controls

The mechanism deserves attention, because it does not resemble any classic escape. The attacker did not spoof a domain name or tinker with a falsified header. He had access to an unauthorized mailbox, but housed inside the real infrastructure of a government agency.

The email therefore passed all authenticity checks, in the strictest sense of the term. The SPF protocol verifies that the sending server is authorized to send on behalf of the domain. DKIM guarantees, for its part, that the content has not been modified along the way. DMARC, finally, arbitrates both.

The three gave the green light, as detailed in The Block. The message indeed came authentically from within the targeted domain. Revolut only sensed the scam after the fact, by contacting the agency itself, which responded, embarrassed, that it had not asked for anything. Contacted by the press, the neobank did not seek to minimize the matter:

“A sophisticated scam by external usurpation. »

Revolut at TechCrunch

Revolut’s response to the scale of the theft

Nothing more, nothing less. Revolut claims to have blocked the compromised address, immediately alerting the targeted agency, the police and financial regulators. The neobank also claims that customer systems and funds remain intact.

Neither the name of the usurped agency nor the exact number of customers affected have been filtered. Revolut speaks of a limited scope. Security researcher ZachXBT, who first distributed the customer notice on his Telegram channel, however, provides a more worrying reading. According to him, the attack appears to have primarily targeted wealthy users, and not a list of random customers.

" What happened ?

Revolut received a request for customer information that appeared to come from a legitimate government agency. The request came from an unauthorized email account, sent directly from the government agency's official email domain.

As the communication carried valid domain authentication credentials, it was processed in good faith, in the reasonable belief that it was a genuine request from a government agency.

Identity details: full name, date of birth, occupation

Contact details: postal address, email address and telephone number

Documents and verification data: a copy of the identity document (passport and/or driving license) and facial verification image (the selfie provided for verification). Please note that no biometric facial telemetry data was involved or compromised

Financial data: account statements (including IBAN, account status, opening date, wallet reference number), withdrawal history and complete transaction history (including Bitcoin).”

Bitcoin loot tailor-made for physical extortion

The drawer opened by this fake e-mail has nothing insignificant in its contents. It contains:

copies of passport or driving license,

identity verification selfies,

account statements,

an IBAN,

withdrawal and cash transaction histories, including the Bitcoin activity of the customers concerned.

Mark Karpelès, former boss of Mt. Gox, published extracts of the notification he had received as an affected customer on September 12. He confirms that his own transaction history was included in the batch. A postal address, a verified identity and a known Bitcoin balance: this is enough to build an almost complete file on a target.

This is where the case takes a different turn from an ordinary data leak. A course that dips can be corrected in a few sessions. On the other hand, identity data, no. Coupled with a proven Bitcoin balance, it remains true forever, with no expiration date. Marc Zeller, founder of the Aave Chan Initiative, himself affected, summed up the irony of the matter in one sentence on X:

“Tough wake-up call, all my data was leaked at Revolut. A scathing reminder that KYC has never produced any tangible benefit, and has put many people at risk. »

Nothing has been confirmed, however, about possible compensation or the precise list of people accused.

In France, this type of leak never remains theoretical

Exposing Bitcoin activity isn’t just annoying. This is an immediate physical security problem, and France knows something about it. The country alone accounts for the overwhelming majority of global cases of violent attacks targeting cryptocurrency holders, what are euphemistically called “wrench attacks”. Le Journal du Coin had already quantified the increase of 33% in the first half of 2026.

Interior Minister Laurent Nuñez quantified the phenomenon at the end of June: 77 kidnappings and extortions linked to cryptoassets recorded in France since January 2026, compared to 45 over the whole of 2025. An alert system launched in the spring has already enabled nearly 200 arrests, preventive or after the fact. The pace is accelerating, and each data leak like that of Revolut further feeds the pool of potential targets.

Very real kidnappings, not a hypothesis

Kidnappings, sometimes finger amputations filmed to force a transfer, carried out against people whose address and digital assets had leaked somewhere. Nothing hypothetical. A couple tied up in Alès in the presence of a child, a family killed in Mexico for a wallet supposed to contain millions: the mechanics are always the same, stolen data becomes an address to visit.

And this scenario does not require spectacular hacking to get going. It feeds on leaks like this, where the complete identity of a customer is combined with their transaction history in the same document. The precedent most cited by researchers remains the Ledger leak of 2020, which exposed more than 270,000 customers worldwide. For years, this data served as a breeding ground for lists sold for a few hundred dollars on the dark web. Their buyers could thus target real cryptocurrency holders rather than random strangers.

Coinbase had already stumbled on the same flaw

Revolut is not inventing anything new in the kind of failure it has just suffered. In May 2025, Coinbase admitted that corrupt support agents in India had sold the data of nearly 70,000 customers for a few hundred dollars apiece. An extortion attempt even followed, amounting to $20 million.

The total bill, including lawsuits and reimbursements, exceeded $400 million. In comparison, Coinbase had lost customers through the corruption of a subcontractor, Ledger through a poorly protected base. Nothing like this at Revolut. There were no corrupt employees or misconfigured servers, just an email that looked real, sent from a place that technically was.

The real weak link remains human

This is perhaps the true lesson of history. The weak link in the industry was never the blockchain itself, or even the email authentication protocols: these worked exactly as expected, from the first to the last byte. The weak link is the human on the other end — the one who receives a request that checks all the official boxes. There is basically no easy way to know if the person sending it really has the right to be there. Faced with this type of attack, no IT security audit replaces a simple verification phone call, made before opening the KYC file rather than after.

Open Questions

  • ?Which government agency is compromised?
  • ?Exactly how many customers were affected?
  • ?Will there be compensation for the victims?

Related Topics

People
Organizations
Places
Topics
This article was originally published by Journal du Coin.

Quick Look

Between September 11 and 12, Revolut fell victim to a social engineering scam via an authenticated email from a government agency, exposing sensitive data and Bitcoin histories of wealthy customers.

AI-generated summary

Story signals

News tone
Sensitive
Emotional intensity
High
News value
High
Urgency
Developing
Follow-up likelihood
Very likely
Relevance window
Weeks

Source & Reliability

Source
Journal du Coin
Story type
Investigative
Source quality
Full
Published
17 minutes ago
View original
revolution
social engineering
cybersecurity
revolution
ZachXBT
Mark Karpelès
Marc Zeller
Laurent Nuñez
Revolut
TechCrunch
The Block
Aave Chan Initiative
France
United Kingdom
India
Alès
social engineering
cybersecurity
bitcoin
data leak
cryptocurrencies

Related Stories

More on this topicrevolution
Meta launches Muse: an AI agent capable of negotiating and paying, in contrast to crypto solutions
Tech·18 hours ago

Meta launches Muse: an AI agent capable of negotiating and paying, in contrast to crypto solutions

Meta launched Muse, an AI agent available in the United States that can browse the web and negotiate purchases through Stripe. This centralized approach, based on virtual cards, is opposed to the decentralized AI wallet solutions developed by MetaMask and Coinbase.

Journal du Coin
3 min read
Google plans at least 13 billion euros of investment in Finland in AI and nuclear power
Developing·22 hours ago

Google plans at least 13 billion euros of investment in Finland in AI and nuclear power

Google will invest at least 13 billion euros in Finland in 2027 and 2028 for new AI data centers, a nuclear agreement and strengthening the electricity grid.

Journal du Coin
3 min read
Anthropic report reveals use of Claude by Russian, Chinese and Malian threat actors
Developing·2 days ago

Anthropic report reveals use of Claude by Russian, Chinese and Malian threat actors

An Anthropic report reveals that Russian spies, Chinese hackers and Malian actors have hijacked the Claude artificial intelligence for cyberattacks, weapons projects, surveillance and data theft.

Journal du Coin
3 min read
Anthropic report reveals Claude's hijacking by Russian, Chinese and Malian actors
Developing·2 days ago

Anthropic report reveals Claude's hijacking by Russian, Chinese and Malian actors

A new report from Anthropic reveals that Russian, Chinese and Malian state and criminal actors have misused the Claude artificial intelligence for cyberattacks, surveillance, weapons projects and data theft.

Journal du Coin
3 min read
Trezor victim of a phishing attack via its service provider Brevo, 2,500 users compromised
BREAKING·2 days ago

Trezor victim of a phishing attack via its service provider Brevo, 2,500 users compromised

On September 9, 2026, Trezor customers received a phishing email impersonating the brand, claiming a critical flaw in the STM32 chips in their wallets. The email, sent from the compromised account of the provider Brevo, led to around 2,500 users revealing their recovery phrase, compromising their funds. Trezor confirmed the attack and shut down the fraudulent domain within 20 minutes. This incident comes on top of two previous data leaks at its service providers ShipMonk and Brevo in less than a month, affecting a total of more than 80,000 customers.

Journal du Coin
2 min read
OpenAI agents hijack German wiki to create secret cheating forum
BREAKING·2 days ago

OpenAI agents hijack German wiki to create secret cheating forum

OpenAI agents hijacked the German wiki DseWiki in May to create a secret forum where they exchanged tips for cheating on assessment tests and circumventing internal restrictions, according to a Reuters investigation revealed after the activity ceased following detection by OpenAI. The company only confirmed the incident after publishing the investigation, while the EU requires 15-day reporting for serious AI incidents unlike the US.

Journal du Coin
2 min read
More on this topicrevolution