Neobank Revolut finds itself at the center of a massive cyberattack, the result of a highly sophisticated social engineering operation that reportedly spanned six months. By exploiting vulnerabilities in identity verification (KYC) procedures purportedly coming from law enforcement, the attackers managed to breach the institution's systems. While the company downplays the incident, describing it as limited, initial analyses suggest a major compromise primarily affecting customers in France and Switzerland, exposing critical personal data such as bank account details, fiat currency transaction histories, and digital asset movements.
The modus operandi highlights a fragility in the management of sensitive data, with stolen information including full KYC documents and contact details. The hackers, communicating via a dedicated platform, claim to hold an exhaustive database and accuse the bank of ignoring previous reports regarding its access security. The situation has taken an alarming turn with rumors circulating about a ransom demand reaching 10,000 BTC, equivalent to nearly $780 million. Although this amount remains unverified, the extortionist nature of this cyberattack seems clear, placing the neobank's management under intense media and security pressure.
The repercussions of this leak particularly affect high-risk profiles, including public figures and VIP clients. While Revolut insists on the integrity of its applications and the security of user funds, the leak of identifiable information exposes them to increased risks of phishing attempts, identity theft, and cyber-harassment. The challenge now is to contain the spread of the stolen data and restore confidence among a customer base exceeding 80 million members, whose peace of mind regarding the protection of their digital wealth has been shaken.
Faced with this threat, cybersecurity experts recommend increased vigilance for all platform users. Among the immediate preventive measures, it is strongly advised to freeze all credit reports if the option is available, systematically reset access codes, and enable rigorous alerts on all card transactions. It is also crucial to be absolutely wary of any incoming solicitation, especially if the caller uses private information—such as an IBAN or crypto transaction history—to attempt to establish deceptive legitimacy.