Between September 11 and 12, scammers exploited unauthorized access to a government agency’s email domain to extract sensitive customer data from Revolut, including passports, verification selfies, and Bitcoin transaction histories. The email bypassed all authentication checks (SPF, DKIM, DMARC) because the attacker was operating from inside the agency’s actual domain. Mark Karpelès, former CEO of Mt. Gox, and Marc Zeller, founder of the Aave Chan Initiative, are among the identified victims. The neobank, which recently obtained full banking authorization in France in August 2026 and is exploring a stock market listing at a valuation of 150 to 200 billion dollars, denied any theft of funds while alerting regulators. In France, 77 kidnappings and extortion attempts linked to crypto assets have been recorded since January 2026, compared to 45 for all of 2025, making this data breach particularly alarming for the physical security of those affected.
Source: Read the original article

