Revolut Data Breach Escalates: Customer Identities and Bitcoin Records Leaked, Ransom Demanded
A recent data incident at Revolut, initially reported as an erroneous disclosure stemming from a sophisticated impersonation scam, has taken a perilous turn. Attackers claiming to possess a trove of sensitive customer information—including identity documents, account records, and even Bitcoin transaction histories—have now begun publicly releasing portions of this data and issued a ransom demand. They threaten to publish more customer profiles daily if Revolut refuses to comply.
According to a September 14 report by UK financial media outlet City AM, an organization identifying itself as “Revolut Smilik” confirmed to the media that it is demanding payment from Revolut. The group has leveraged Telegram to issue threats of releasing “more and more data, published every day.” The report further indicates that data belonging to some prominent individuals has already been made public. Revolut, for its part, has declined to disclose the exact number of affected customers and has not commented on whether it intends to meet the extortion demands.
This development signifies a critical escalation, transforming what was a data disclosure error into a complex “secondary extortion” crisis.
Sensitive Data Compromised: Passports, Selfies, and Crypto Transaction Histories at Risk
Revolut has confirmed that the root of the incident was a “sophisticated external impersonation scam.” Unauthorized individuals successfully exploited an email account within a legitimate government agency’s domain to send data requests. This tactic led Revolut to believe the requests were legitimate, resulting in the handover of sensitive customer data.
While Reuters, citing Revolut, reported that the incident impacted a “very limited” number of customers and that the company’s core systems and customer funds remain uncompromised, the nature of the exposed data is deeply concerning. Customer notifications reveal that the compromised information extends far beyond basic names or email addresses. It includes:
- Date of birth
- Residential address
- Phone number
- Copies of passports or driver’s licenses
- Identity verification selfies
- Account statements
- IBANs
- Withdrawal records
- Complete transaction histories, potentially including Bitcoin transaction records
Recent leaks confirm that the attackers have indeed started publishing what they claim are victims’ identity documents and verification photos. Data allegedly linked to public figures began circulating on platforms like X (formerly Twitter) and Telegram as early as September 13.
The UK Information Commissioner’s Office (ICO) has confirmed to City AM that it has received Revolut’s incident report and is currently assessing the information. This incident is particularly noteworthy as it does not involve a traditional database hack. Instead, attackers leveraged “legitimate government email infrastructure” to circumvent Revolut’s internal verification processes. This highlights a broader challenge for financial institutions: ensuring robust second-layer verification mechanisms when responding to law enforcement and government data requests, even when communication channels appear authentic.
Revolut reiterates that its core infrastructure, databases, and customer accounts were not breached. However, this incident underscores a growing and difficult-to-mitigate risk for financial entities: criminals can obtain highly sensitive Know Your Customer (KYC) and financial data by controlling or misusing trusted government communication channels, even without directly “hacking” the bank itself.
Heightened Risks for Cryptocurrency Users: Beyond Identity Theft
This data breach carries particularly severe implications for cryptocurrency users.
While conventional identity data breaches typically expose individuals to risks like phishing, SIM swapping, account takeovers, or general identity theft, the simultaneous exposure of real names, addresses, passport details, and complete Bitcoin transaction histories presents a unique and elevated threat. Such a combination could enable attackers to directly link an individual’s physical identity to specific on-chain crypto asset activities.
On-chain investigator ZachXBT previously speculated that the incident might involve the targeted compromise of high-net-worth individuals. However, Revolut has yet to disclose the total number of affected users or confirm whether the breach disproportionately impacts high-value clients.
Consequently, while it’s premature to definitively label this as an attack specifically targeting crypto millionaires, the convergence of KYC data, residential addresses, and on-chain activity in the hands of criminals undeniably poses risks far greater than those associated with a typical email address leak.
The Unfolding Crisis: Key Questions Remain Unanswered
As of the evening of September 14, Revolut has not publicly confirmed several critical details, including the precise number of affected customers, the name of the government agency whose domain was impersonated, or the specific ransom amount demanded by the attackers.
What is unequivocally clear is that the situation has escalated from an “erroneous delivery of customer data” to a public extortion attempt, with attackers actively publishing what they claim to be stolen customer data. The threat of “daily” continuous leaks remains an attacker’s claim, and the industry awaits further developments to ascertain if these daily disclosures will indeed materialize.
Disclaimer: This article is intended solely for market information purposes. All content and views are for reference only and do not constitute investment advice, nor do they represent the views and positions of BlockTempo. Investors should make their own decisions and trades. The author and BlockTempo will not bear any responsibility for direct or indirect losses resulting from investor transactions.