Home NewsRevolut Hacker Attack: Are Your Savings at Risk?

Revolut Hacker Attack: Are Your Savings at Risk?

Hackers breach Revolut customer accounts using compromised government channels. Find out if your financial data and identity are at risk.

by Emanuela Colatosti

A sophisticated cyberattack recently compromised sensitive customer records at Revolut, Europe’s largest digital banking platform. Cybercriminals tricked the fintech firm into handing over private identification files, residential addresses, and financial histories belonging to hundreds of high-net-worth clients. The attackers executed the scam by impersonating government officials through authentic official email domains, bypassing standard compliance checks.

Exploiting Official Communication Channels

The security breach occurred after hackers gained unauthorized control of an official Certified Electronic Mail account belonging to Italian law enforcement agencies. Cybercriminals deployed infostealer malware on an employee computer, harvesting internal login credentials and session cookies. Once inside the system, the attackers established silent access and monitored communications without alerting internal IT security teams.

Using this legitimate government domain, the hackers issued a fraudulent European Investigation Order demanding immediate access to targeted customer accounts. Believing the request originated from genuine law enforcement authorities, Revolut compliance teams transferred approximately one hundred and forty-seven gigabytes of confidential customer data without secondary verification.

Targeted High-Net-Worth Accounts and Extortion Threats

The stolen database contains critical personal information, including passport scans, facial verification photos, bank account numbers, and cryptocurrency transaction histories. The breach directly impacted nearly seven hundred high-profile users, including tennis star Alexander Shevchenko and Gamdom CEO Felix Römer. The hacker group behind the attack, operating under the alias IAmNotAVillain, published biometric selfies and private files online to pressure the company into paying a ransom.

Revolut confirmed the impersonation scam and immediately blocked the compromised email domain. The fintech firm notified affected customers and data protection watchdogs, asserting that core operational systems and client financial deposits remain fully secure.

Political Fallout in Italy and Emergency Parliamentary Inquiry

The incident triggered immediate political fallout within the European Union, raising serious concerns regarding government infrastructure security. Italian Member of Parliament Giulia Pastorella filed an urgent parliamentary inquiry demanding answers from the Ministry of the Interior. Pastorella raised critical questions about how malware compromised strategic state computers without detection.

Lawmakers emphasized that hijacked government email accounts create dangerous precedents. If hackers can freely manipulate state infrastructure, other financial institutions and private corporations could fall victim to similar state-level deception.

The Response from National Cybersecurity Agencies

Following the breach disclosure, national cybersecurity authorities in Italy and the United Kingdom launched emergency protocol reviews. The Italian National Cybersecurity Agency naturally faces growing pressure to audit institutional networks and enforce stricter two-factor access controls across all government offices. Authorities aim to prevent external actors from abusing official domains to steal citizen data.

Simultaneously, financial regulators are reassessing verification standards for digital banks. Relying solely on domain authentication is no longer sufficient. Moving forward, platforms like Revolut will likely face mandates for dual-channel verification before surrendering sensitive user records to law enforcement requests.

You may also like

Leave a Comment