Revolut has confirmed that a limited number of its customers had their personal and financial information exposed after the company fell victim to a sophisticated social engineering attack. The incident involved an unauthorized third party who utilized a legitimate government agency email domain to submit fraudulent requests for sensitive data. Revolut stated that the breach was not an intrusion into its internal systems, but rather a result of staff being deceived by the impersonation scam.
The exposed data includes sensitive know-your-customer (KYC) documentation, such as copies of passports and driver's licenses, as well as verification selfies submitted during account registration. According to reports, the compromised records also contain account statements, IBANs, withdrawal records, and full transaction histories, including Bitcoin activity. Personal details such as full names, dates of birth, home and email addresses, phone numbers, and occupations were also accessed by the attackers.
While Revolut has not disclosed the specific government agency involved or the exact number of affected individuals, the company confirmed it has contacted those impacted directly. The fintech firm stated that it detected the activity, blocked the fraudulent email address, and alerted relevant government officials, enforcement agencies, and financial regulators. Revolut emphasized that its internal systems and customer funds remain unaffected by the incident.
Individuals claiming responsibility for the attack have appeared in various Telegram groups, where they have shared snippets of data allegedly belonging to high-profile figures, including CEOs and performing artists. These actors are currently demanding a ransom of 10,000 Bitcoin, equivalent to more than $782 million, and have threatened to release additional data if their demands are not met. Revolut has not commented on the ransom demands.
Security experts warn that the primary risk to affected customers is the potential for second-stage fraud, such as identity theft or targeted phishing attempts. Customers are advised to remain vigilant against unexpected contact claiming to be from Revolut, particularly communications that request account security actions or document replacements. Revolut recommends that users report any suspicious activity through its official in-app chat and monitor their accounts for unauthorized transactions or credit applications.
