Cybercriminals, who obtained confidential data belonging to some of Revolut’s customers through fake requests made in the name of a government body, have begun publishing the stolen material and are demanding a ransom. They are threatening further leaks. The company states that its systems and users’ funds have not been compromised, but has not disclosed the extent of the data breach.
Briefly about the main points
- Cybercriminals are publishing some of Revolut’s customer data.
- They are demanding a ransom and threatening further leaks.
- The information was obtained via fraudulent requests sent from a government domain.
- Documents, IBANs and transaction histories may have been at risk.
- Revolut denies that its systems or customers’ funds have been compromised.
The scheme was based on posing as a government body
According to Revolut, a third party sent requests for customer information from an email address on a legitimate government agency domain. The company described this as a sophisticated external scheme to pose as representatives of the organisation.
According to the available information, the attackers did not need to gain direct access to the fintech company’s infrastructure. The use of a genuine government email domain helped to convince Revolut staff that the requests were legitimate.
Hackers are publishing documents and threatening further leaks
According to Blockonomi, personal documents and materials relating to Revolut’s customer verification process have already appeared online. The attackers are demanding a ransom in cryptocurrency and threatening to continue publishing the information.
Specialist media outlets report that the attackers may have gained access to names, dates of birth, telephone numbers, email addresses and postal addresses. The list of potentially compromised information also includes copies of passports and driving licences, as well as photographs and selfies used for verification purposes.
The financial data may have included bank statements, IBANs, withdrawal records and a full transaction history. Cryptocurrency transactions, in particular Bitcoin transactions, are mentioned separately. Revolut has not disclosed a full list of the information compromised or the exact number of people affected, referring to them as a ‘limited number of users’.
Revolut states that customers’ funds have not been compromised
Revolut states that the company’s systems and customers’ funds have not been compromised. This refers to the unauthorised disclosure of data, rather than confirmed direct access by attackers to bank accounts.
After uncovering the scam, Revolut blocked the email address used and stopped processing any requests linked to it. The company also notified the affected users directly.
According to Revolut, the incident was reported law enforcement officers, data protection authorities, financial regulators and the relevant government body. The investigation is ongoing.







