Group used fake government requests and infostealers; targeted accounts with significant crypto holdings identified via blockchain scanning.
Briefing
Revolut suffered a prior breach when attackers used social engineering to access a customer support database, exposing data on 50,000 users. Regulators in Lithuania, where Revolut holds its EU banking licence, opened an inquiry. The recurrence pattern raises supervisory tolerance questions.
Bitfinex hackers demanded ransom in Bitcoin before DOJ recovered 94,000 BTC. The case demonstrated that even pseudonymous ransoms can be traced and seized, which accelerated threat actor migration toward Monero specifically for its unlinkable ring signatures and stealth addresses.
Twitter's July 2020 hack used social engineering against internal employees via fake IT requests to hijack high-profile accounts for Bitcoin fraud. The mechanism is directly analogous: fake authority requests bypassing technical controls rather than exploiting software vulnerabilities.

The Clarity Act's failure in a 49-50 cloture vote leaves US crypto platforms without a federal incident-disclosure or liability framework, meaning Revolut and similarly structured platforms face no standardised reporting obligation or regulatory safe harbour when breaches occur.

DOJ charges against two ex-Robinhood engineers for front-running crypto listings signal prosecutors are actively expanding crypto-specific enforcement; a $3M Monero ransom demand tied to a regulated neobank's customer data is likely to attract parallel DOJ interest given demonstrated appetite for crypto-crime prosecution.
See Indexa more often on Google
Mark Indexa as a preferred source — your Top Stories will surface more Indexa coverage.

11 hours ago