Hackers steal millions after cracking Revolut payment systems

Data Breach
Image Credit: Shutterstock (Image credit: Shutterstock)

Payments giant Revolut has reportedly suffered a cyberattack which resulted in the company losing around $20 million.

A report from the Financial Times citing multiple unnamed people allegedly familiar with the incident noted that the stolen money belonged to the company, not its customers. 

The breach was not publicly disclosed, and Revolut decided not to comment on the attack. 

Refunding expensive purchases

There appears to be quite the discrepancy between how Revolut operates in the US, and how it operates in Europe. The resulting bug allowed users to have a payment declined, and then have Revolut refund the money that was never sent. The bug was apparently first spotted in late 2021, but before Revolut could patch the hole, cybercriminals found it and started exploiting it. No malware seems to have been involved.

As it turns out, cyber-criminals were encouraging people to make expensive purchases that would be declined, and would then withdraw the refunded money from ATM machines. Some $23 million were sent from Revolut this way, but the company managed to claw back roughly $3 million, it would seem.

Some reports have claimed that Revolut did not even initially know it was being robbed, and that it only realized after a partner bank in the US said it was holding less money than expected. Then, the US subsidiary asked for a cash injection in “millions of dollars” from its parent company, before closing the flaw in spring last year.

Revolut is a global financial technology company offering banking services, also known as “neobanks”. The company is licensed and regulated by the Bank of Lithuania within the European Union, and has its headquarters in London, UK. Revolut was founded in 2015 by Nikolay Storonsky and Vlad Yatsenko. 

Besides the “traditional” banking services, Revolut also allows its users to delve into cryptocurrencies, and even trade on the platform.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Ethereum
Hackers steal over $1bn in one of the biggest crypto thefts ever
Russian flag on a laptop
Major Russian IT service provider hit with cyberattack
An abstract image of digital security.
Orange confirms it suffered breach after hacker leaks company documents
Close up of a person touching an email icon.
Top US mineral firm hit by cyberattack that saw thieves steal $500,000
ransomware avast
Billions of credentials were stolen from businesses around the world in 2024
Latest in Pro
Branch office chairs next to a TechRadar-branded badge that reads Big Savings.
This office chair deal wins the Amazon Spring Sale for me and it's so good I don't expect it to last
Saily eSIM by Nord Security
"Much more than just an eSIM service" - I spoke to the CEO of Saily about the future of travel and its impact on secure eSIM technology
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
FlexiSpot office furniture next to a TechRadar-branded badge that reads Big Savings.
Upgrade your home office for under $500 in the Amazon Spring Sale: My top picks and biggest savings
Beelink EQi 12 mini PC
I’ve never seen a PC with an Intel Core i3 CPU, 24GB RAM, 500GB SSD and two Gb LAN ports sell for so cheap
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring