Global fintech platform and licensed crypto asset service provider Revolut disclosed a targeted cybersecurity incident after unauthorized third parties utilized a compromised government communication channel to extract restricted customer records. The intrusion, flagged by automated internal threat telemetry, affected employee workstations and exposed specific metadata linked to a subset of the neobank's international client base.
Revolut verified that core banking ledgers, fiat balances, cryptocurrency cold storage, and private cryptographic keys remained fully isolated throughout the event. Multi-factor authentication mechanisms and raw payment card credentials were also unaffected. In accordance with Article 33 of the General Data Protection Regulation (GDPR), the company formally notified supervisory authorities across the United Kingdom and the European Union.
Attack Vector: Weaponization of Official Channels
Technical disclosures indicate the intrusion relied on sophisticated spear-phishing vectors originating from authenticated government email accounts. By routing deceptive administrative queries through bona fide public sector infrastructure, the threat actors bypassed baseline email security gateways, gaining an initial foothold into administrative tools that handle non-financial customer identity parameters.
Latest Market Updates & Breaking Developments
In the latest development, Italian law enforcement and cybersecurity oversight agencies have formally launched an investigation into the compromised government email system weaponized during the incident. The inquiry seeks to identify how unauthorized actors gained control over state-sanctioned communications relays to execute targeted social engineering attacks against financial institutions.
European data protection agencies are collaborating to trace the threat actor's telemetry and determine whether additional financial institutions or virtual asset service providers (VASPs) were targeted using the same administrative vector. The incident highlights critical third-party counterparty risks where trusted public-sector domains can be weaponized against institutions enforcing strict internal defense perimeters.
“The weaponization of authenticated sovereign email infrastructure fundamentally undermines traditional perimeter security models for digital banks. When an intrusion leverages cryptographically verified state relays, the point of failure shifts from internal operational security to inter-institutional trust architectures, necessitating cryptographic verification protocols for sensitive regulatory data exchanges.” — Marco Vianelli, Head of Enterprise Threat Intelligence at CyberRisk Europe.