Key Points
- Cybercriminals successfully impersonated government authorities to obtain confidential customer information from Revolut
- Approximately 680 users had sensitive information compromised, including identification documents, financial records, and cryptocurrency transactions
- Extortionists are demanding payment of 10,000 Bitcoin (approximately $780 million) and threatening ongoing data leaks
- UK regulatory authorities have initiated a formal investigation into the incident
- The security incident may impact Revolut’s upcoming initial public offering valued at $200 billion
Revolut has acknowledged falling victim to a sophisticated social engineering attack where cybercriminals successfully obtained confidential customer information by impersonating government representatives. The security incident has impacted approximately 680 account holders.
The perpetrators transmitted a deceptive data request utilizing an authentic governmental email address. Revolut’s team processed the request and disclosed confidential customer information including passport documentation, financial account identifiers, residential addresses, identity verification photographs, government-issued identification cards, and records of Bitcoin transactions.
Following the data acquisition, the cybercriminals initiated extortion attempts, threatening public disclosure of the stolen information without payment. The ransom figure has been disclosed as 10,000 Bitcoin, valued at approximately $780 million based on current market rates, with Bitcoin trading near $77,974.
Compromised Information Details
The pilfered data encompasses transaction records, account documentation, identity verification selfies, and photographs of official identification documents. Contact information including telephone numbers and physical addresses were also exposed.
Blockchain analyst ZachXBT indicated through Telegram communications that the operation appears specifically designed to target wealthy individuals. Evidence circulating online demonstrates the attackers have already begun publishing stolen data, including information belonging to Felix Römer, chief executive of cryptocurrency gambling platform Gamdom.
Mark Karpelès, the former chief executive of defunct cryptocurrency exchange Mt Gox, was also identified among the victims. He received notification from Revolut on September 12 at 5:25 a.m., alerting him to potential data exposure. Karpelès has publicly stated that Revolut should not have disclosed the information even if the request appeared authentic.
The threat actors have alleged that Revolut demonstrated negligence and inappropriately transmitted customer data to international jurisdictions beyond its operational authority.
Company Statement and Regulatory Response
Revolut has characterized the incident as a “sophisticated external impersonation scam.” The organization stated it immediately blocked the fraudulent email address upon discovering the deception.
The fintech company has notified appropriate regulatory bodies and established direct communication with all impacted customers. Revolut proactively reported the breach to the UK’s Information Commissioner’s Office, which confirmed Monday the launch of a formal inquiry.
The digital banking platform has dedicated weekend resources to addressing the crisis. Company representatives described the number of compromised accounts as “limited.”
The incident arrives at an inopportune moment for Revolut. The company has been advancing preparations for a public market debut with an anticipated valuation near $200 billion, substantially exceeding its latest private funding round valuation of $75 billion.
A security compromise of this magnitude, coupled with substantial extortion demands and active regulatory scrutiny, introduces significant complications to these expansion objectives.
The extortionists have allegedly announced intentions to continue publishing customer information on a daily basis until their ransom demands are satisfied. No confirmation of payment has been reported.


