Revolut Crypto Whale Data Breach Claim: How to Protect Against Targeted Wallet Scams
Hackers claim they obtained data on hundreds of Revolut customers by abusing an Italian government email system. Crypto holders should prepare for targeted phishing.
Crypto Support & Research Desk
Revolut Crypto Whale Data Breach Claim: How to Protect Against Targeted Wallet Scams
Quick answer: Hackers have claimed they obtained sensitive information on roughly 680 Revolut customers, particularly people with significant crypto holdings, by abusing an Italian government email channel to impersonate law enforcement. Revolut says its internal systems were not breached. The immediate customer risk is targeted social engineering.
What has been reported
The Financial Times reported that attackers claimed they compromised Italy's certified government email infrastructure and used it to send apparently official information requests to Revolut. The attackers said the resulting data covered customers across multiple European countries. Italian authorities are investigating, while Revolut maintains its own systems remained secure.
Why crypto holders should take this seriously
A targeted scam is more dangerous than generic phishing because an attacker may know your name, region, account relationship or that you hold crypto. That context can make a fake support, police, compliance or wallet-security message look convincing.
Lock down account access
- Use a unique password for financial accounts.
- Enable the strongest available multi-factor authentication.
- Review active sessions and devices.
- Secure the email account tied to financial services.
- Add carrier protections against SIM swaps where available.
Treat unexpected support or police contact as untrusted
Do not move crypto because an unsolicited caller, email or direct message says your funds are at risk. End the conversation and open the official app or website yourself. Never install remote-access software, reveal a seed phrase, or transfer funds to a so-called safe wallet.
Self-custody users need a separate defense
If an attacker learns that you hold crypto, they may impersonate a wallet vendor rather than Revolut. Hardware-wallet and self-custody recovery phrases should never be entered into a website reached through an email or message.
Preserve evidence if targeted
Keep screenshots, sender addresses, phone numbers and message headers where practical. Do not click links merely to investigate them. Report suspicious contact through the official provider and, if credentials were exposed, secure linked accounts quickly.
Source
The incident claim was reported by the Financial Times. Treat the investigation as developing and distinguish the alleged government-email abuse from a direct breach of Revolut's systems.
FAQ
Was Revolut itself hacked?
Revolut says its internal systems remained secure.
Why does this matter to crypto users?
Personal context can make impersonation and wallet phishing much more convincing.
Will support ask for a seed phrase?
No. Never disclose a self-custody recovery phrase.
Informational only, not investment advice. Security investigations can change as new evidence emerges; verify alerts through official channels.
Informational only, not investment advice.
About the Author
Crypto Support & Research Desk
Crypto Support Desk publishes practical, source-led guides to exchange, wallet, network and on-chain service changes. Information is checked against primary or reputable security sources and is not investment advice.