Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

coincentral+1coindeskinsurancebusinessmagRevolut confirmed on September 12 that it disclosed sensitive customer data to an unauthorized party after fraudulent requests arrived from an email address on a legitimate government agency domain, in what the fintech is calling a "sophisticated external impersonation scam." The attackers have since begun publishing stolen records and are demanding a ransom of 10,000 Bitcoin — roughly $780 million — threatening to release more data daily if Revolut does not pay.coincentral+3
The breach affected approximately 680 customers across multiple countries, including 12 in Ireland, 25 in Spain, and 27 in Romania, according to reporting by the Financial Times carried by Investing.com. The UK Information Commissioner's Office has confirmed it received a report from Revolut and is assessing the incident, while the Financial Conduct Authority said it was engaging with the firm.insurancebusinessmag+2
The data handed over was unusually comprehensive for a single incident. According to CoinDesk, the files included passports or driver's licenses, verification selfies, names, dates of birth, occupations, home addresses, emails, phone numbers, IBANs, account statements, withdrawal records, and full transaction histories including all Bitcoin activity. Revolut's own notification to customers confirmed this scope.helpnetsecurity+2
The combination of identity documents and Bitcoin transaction data is what distinguishes this breach. Bitcoin transactions are publicly visible on the blockchain but pseudonymous; pairing wallet references with a verified name and passport scan effectively strips that pseudonymity, making affected customers potential targets for phishing, extortion, or worse.coindesk+1
No one broke into Revolut's servers. The attacker sent data requests from what appeared to be a genuine government agency email domain. The messages passed Revolut's technical authentication checks — SPF, DKIM, and DMARC — and were processed as standard legal-compliance requests. Revolut only discovered the fraud after separately contacting the agency and learning the requests were not legitimate.coindesk+2
Former Mt. Gox CEO Mark Karpelès noted on social media that a file posted by the attackers appeared to be a raw email sent through Italy's PEC certified mail system, which Italian authorities use for official legal correspondence. Cybernews reported that the hacker claimed the breach lasted six months.x
"Most of the successful attacks impacting our insureds come from human error," Simon Hughes, chief commercial officer at Cowbell Cyber, told Insurance Business. "Accidentally clicking on a link, accidentally responding to someone you shouldn't."insurancebusinessmag
The attackers have claimed responsibility on Telegram and begun publishing stolen records, including identity documents belonging to tennis player Alexander Shevchenko and Gamdom CEO Felix Römer, according to International Cyber Digest. The 10,000 BTC demand remains unconfirmed by Revolut, which has declined to comment on the extortion.cryptoticker+2
Revolut, which serves more than 80 million customers and was valued at $115 billion in a secondary share sale earlier this year, has stressed that its core banking systems and customer funds were not compromised. But for the roughly 680 people whose passports and biometric selfies are now circulating online, that distinction offers limited comfort.reuters+1