A Government-Email Impersonation Scam Exposes Crypto Customer Data

Revolut, the European fintech giant and self-described largest financial technology company in the region, has confirmed that it was targeted by a sophisticated impersonation scheme earlier this month. According to the company, an unauthorised third party compromised an Italian government email system and used that legitimate domain to send fraudulent information requests directly to Revolut staff. The requests were designed to extract personal customer details, and the bank says it detected the fraud, immediately blocked the offending address, and notified the relevant government agency, enforcement bodies, data-protection authorities, and financial regulators.

The breach affected approximately 680 individuals out of Revolut's 80 million global customers, and it is understood that the victims were specifically targeted because of their suspected cryptocurrency holdings. Despite the relatively small number of affected accounts, the incident has escalated into a high-stakes extortion case. The Financial Times reports that one of the alleged hackers has demanded a $3 million (roughly £2.2 million) ransom in exchange for deleting the stolen data, with payment requested through the Monero cryptocurrency — a choice that would leave no verifiable trail of transfer, effectively allowing the criminal to deny ever receiving the funds.

A Revolut spokesperson stated that the bank "has not received any direct contact or demand from the individuals or group making these claims," though victims on the ground paint a different picture.

Victims Report Fears for Their Physical Safety

Among the most vocal victims is Mark Karpelès, the French businessman best known as the former chief executive of the now-defunct Bitcoin exchange Mt. Gox. Karpelès, a Revolut customer since 2023, told the Guardian that his full address and family details appear in the stolen files. "I have kids, we're living together. My address is in those files, so of course I'm worried about this," he said. He posted on X earlier in the week that he feared he could be "kidnapped or dead" before Revolut provided him with more substantial information about the scope of the breach.

Karpelès has since contacted law enforcement in Tokyo, where he resides, and said he was relieved that Japanese officials were taking the threat seriously, though he acknowledged he might need to travel overseas or avoid locations he considers less secure. He noted that the hackers may have mistakenly flagged his account, assuming he was far wealthier than he actually is — Karpelès was forced to declare bankruptcy following a high-profile court case in Japan. He was originally charged with embezzlement after Mt. Gox's collapse in 2014, later acquitted on that charge by Japanese courts, but found guilty of falsifying data. He remains a controversial figure in the cryptocurrency community.

Karpelès has joined a victim chat group on X where affected customers are exchanging information and mutual support. "We're all in the same situation, which is: we don't know exactly what happened, or how it happened, so we're trying to get as much information as possible," he explained. He relayed that at least one fellow victim made direct contact with the purported hacker, who demonstrated possession of the individual's personal details before demanding $50,000 to delete the information.

Implications for Revolut's Market Debut and Brand Trust

The timing of the breach is particularly sensitive. Revolut's founder, Nik Storonsky, told the French publication Les Échos on Thursday that the company still has plans for a dual listing in both London and New York. The firm was valued at $115 billion in a secondary share sale earlier this summer, making any reputational damage a significant concern. Karpelès, while frustrated with Revolut's response, does not believe the company should cave to the $3 million demand, arguing that payment offers no guarantee the data will actually be wiped.

He warned that the incident is "very, very damaging" for the Revolut brand, particularly because a large share of its customer base — especially those active in cryptocurrency — tend to be highly privacy-sensitive. For traders and retail investors, the episode underscores a critical vulnerability: even well-resourced financial platforms can be compromised through social-engineering attacks that exploit trusted institutional channels.

What Traders and Investors Should Take From This Incident

From a scam-alerts perspective, several lessons emerge. First, the attack vector was not a brute-force hack of Revolut's own systems but a social-engineering play that leveraged a legitimate government domain to gain the trust of internal staff. This means that even customers of highly regulated, large-scale financial institutions are exposed when the breach occurs at the human-interaction layer rather than the technical one.

Second, the demand for payment in Monero is a well-known tactic among extortionists, as the coin's privacy features make transactions nearly untraceable. Traders who find themselves on the receiving end of a similar data-theft threat should be wary of any payment instruction that deliberately avoids auditability.

Third, the fact that victims are being individually targeted — with personal addresses, family details, and financial profiles — elevates the risk from a financial one to a physical-safety one. Karpelès's experience illustrates that the consequences of a data breach in the crypto space can extend well beyond a compromised wallet or a stolen login credential.

Revolut's official position is that its core systems and customer funds remain unaffected, and that it has proactively contacted the limited number of impacted individuals to inform them and offer support. However, for traders and investors in the broader forex and digital-asset space, the incident serves as a reminder that impersonation scams of this nature are increasingly directed at the back-office operations of financial firms, and that the exposure risk for end-users can be significant even when the platform itself is not directly compromised.