Key Points
- Cybercriminals successfully impersonated government authorities to extract sensitive customer information from Revolut
- Approximately 680 users had their personal information compromised, including identification documents, financial records, and cryptocurrency transactions
- The threat actors are demanding payment of 10,000 Bitcoin (approximately $780 million) to prevent public disclosure of the stolen information
- British regulators at the Information Commissioner’s Office have initiated a formal inquiry
- The incident poses significant risks to Revolut’s ambitious $200 billion public listing strategy
Revolut has acknowledged falling victim to a sophisticated social engineering attack in which cybercriminals successfully obtained confidential customer information by impersonating government authorities. The security incident impacted approximately 680 users of the platform.
The threat actors utilized a compromised legitimate government email account to submit their fraudulent data request. Believing the inquiry to be authentic, Revolut released sensitive customer information including passport documentation, financial account details, residential addresses, identity verification photographs, government-issued identification cards, and records of Bitcoin transactions.
Following the successful data extraction, the cybercriminals initiated an extortion campaign threatening public disclosure of the stolen information unless compensation was provided. The ransom figure has been established at 10,000 Bitcoin, valued at approximately $780 million based on current market rates of around $77,974 per Bitcoin.
Scope of Compromised Information
The exfiltrated data encompasses a wide range of sensitive materials including complete transaction records, financial statements, identity verification selfies, and scanned copies of official identification documents. Contact information such as telephone numbers and physical addresses were also part of the breach.
According to blockchain researcher ZachXBT’s statements on Telegram, the operation seems specifically designed to target wealthy individuals. Evidence circulating online indicates the attackers have begun publishing stolen records, with Felix Rƶmer, the chief executive of cryptocurrency gambling platform Gamdom, identified as one victim whose information was released.
Mark KarpelĆØs, the former head of the defunct Mt Gox cryptocurrency exchange, also found himself among the victims. He was notified by Revolut on September 12 at 5:25 a.m. that his personal information might be compromised. KarpelĆØs has publicly criticized Revolut’s decision to release the data, arguing that the company should have exercised greater caution regardless of how authentic the request appeared.
The cybercriminals have publicly criticized Revolut for inadequate security practices and for allegedly distributing customer information to governments outside appropriate legal jurisdictions.
Company Response and Regulatory Action
Revolut has characterized the incident as a “sophisticated external impersonation scam.” According to company statements, the fraudulent email address was immediately blocked upon discovery of the deception.
The financial technology firm has confirmed it immediately alerted appropriate law enforcement agencies and personally reached out to every affected customer. Revolut proactively reported the breach to the UK’s Information Commissioner’s Office, which announced Monday that a formal investigation has been launched.
The digital banking platform devoted significant resources throughout the weekend addressing the security incident. Company representatives emphasized that the total number of compromised accounts represents a “limited” portion of its customer base.
This breach arrives at a particularly inopportune moment for Revolut. The company has been preparing for an initial public offering with projected valuations reaching approximately $200 billion, substantially exceeding its latest private funding round valuation of $75 billion.
A security compromise of this magnitude, coupled with substantial ransom demands and active regulatory scrutiny, creates considerable complications for the company’s market debut strategy.
The attackers have allegedly stated they will systematically publish additional customer records daily until their ransom demands are satisfied. No confirmation of ransom payment has been reported at this time.





