Revolut Hacker Targets Crypto Figures With Stolen Data
The threat actor responsible for the Revolut breach is now extorting cryptocurrency industry figures using their personal information, obtained via a compromised government email account.

The cybercriminal behind the recent breach of payments platform Revolut has escalated their activities, now targeting and extorting prominent figures within the cryptocurrency industry. This new wave of attacks involves the use of personally identifiable information (PII) stolen during the initial Revolut compromise. The threat actor has reportedly used a compromised government agency email account to socially engineer their way into Revolut's systems, leading to the theft of sensitive customer data.
Several individuals within the crypto space have confirmed receiving direct extortion threats. These threats leverage the stolen personal information, indicating a sophisticated and targeted campaign. The attackers are exploiting the perceived wealth and public profiles of their victims to coerce them into paying ransoms. The specific nature of the PII stolen has not been fully disclosed, but the extortion attempts suggest it includes details that could be used for further social engineering or to cause personal distress.
The method of initial compromise, utilizing a hacked government email account, highlights a critical vulnerability in how organizations handle third-party access and the potential for supply chain attacks. Government credentials, if compromised, can serve as a powerful tool for attackers to bypass standard security measures and gain access to sensitive corporate networks. This tactic underscores the interconnectedness of digital security and the cascading effects of a single breach.
Revolut has previously acknowledged a security incident where unauthorized access was gained to a third-party vendor's system. While the company stated that customer funds and accounts remained secure, the subsequent targeting of individuals suggests that PII was indeed exfiltrated. The company has been working with cybersecurity experts and law enforcement to investigate the incident and mitigate further damage.
This development poses a significant personal safety risk to the targeted cryptocurrency figures. Beyond financial loss, the exposure of personal details can lead to doxxing, harassment, and other forms of online and offline harm. The attackers' willingness to directly engage in extortion demonstrates a high level of confidence and a disregard for legal repercussions.
Security experts are advising individuals in the crypto industry to be hyper-vigilant regarding unsolicited communications, particularly those that appear to originate from official sources or contain personal information. They recommend reviewing privacy settings, being cautious about information shared online, and preparing for potential follow-on attacks. The incident serves as a stark reminder of the persistent threats facing the digital asset ecosystem and the need for robust security practices at both corporate and individual levels.
While the full scope of the stolen data and the extent of the ongoing extortion campaign are still emerging, this incident points to a concerning trend of threat actors leveraging breaches of financial services and third-party vendors to target high-value individuals. The use of compromised government accounts as an initial vector adds another layer of complexity and concern for cybersecurity professionals.