Revolut Data Breach: Hacker Launches Website to Advertise Stolen Customer Data and Demands $3 Million Ransom

Revolut data breach hacker ransom demand and stolen customer data


The Revolut data breach has taken a more serious turn after a hacker claiming responsibility for the incident reportedly launched a website advertising stolen customer information and demanding a ransom.

The latest development has raised fresh concerns for customers whose personal and financial information may have been exposed. According to reports, the group behind the claim is threatening to sell or release additional information unless Revolut pays the demanded ransom.

The alleged attackers have also reportedly contacted or attempted to pressure people whose information was included in the stolen material, adding a potential blackmail element to an already serious data-security incident.

However, one important detail remains unresolved: Revolut says it has not received a direct ransom demand from the alleged attackers. Reuters reported on September 16 that the company had no direct contact with the individuals or group claiming responsibility, despite reports of a public ransom threat.

What is happening with the Revolut data breach?

Revolut confirmed earlier in September that an unauthorized party had obtained sensitive customer information after fraudulent requests were sent using a legitimate government email domain.

Rather than breaking directly into Revolut's core systems, the attackers allegedly exploited a trusted communication process. The fraudulent requests were presented as legitimate government or law-enforcement requests for customer information.

Revolut said it detected the activity, blocked the relevant address and notified the appropriate government agency, law-enforcement authorities, data-protection bodies and financial regulators. The company has also said that its systems and customer funds were not affected.

That makes the incident particularly notable from a cybersecurity perspective. The reported attack relied on social engineering and impersonation, rather than a conventional intrusion into Revolut's banking infrastructure.

Hacker reportedly demands $3 million

The latest escalation involves an online group identifying itself as "I Am Not A Villain", according to the Financial Times.

The group has reportedly demanded approximately $3 million in Monero (XMR) and threatened to sell the stolen information to other criminals if the demand is not met.

The reported website allegedly contains a countdown and claims that the information will be sold if the ransom is not paid. The Financial Times reported that the group said the demand amounted to 6,000 XMR, equivalent to around $3 million at the time of the report.

The use of Monero is notable because the cryptocurrency is designed to provide greater transaction privacy than Bitcoin, making it a cryptocurrency frequently associated with privacy-focused transactions.

Still, the ransom demand remains a claim made by the alleged attackers. Revolut has said it has not been directly contacted by the group.

Around 680 Revolut customers reportedly affected

The scale of the breach has also become clearer.

The Financial Times reported that approximately 680 customers were affected. The compromised information reportedly included highly sensitive personal and financial records.

Potentially exposed information includes identity documents, account information and transaction histories. Earlier reporting on the incident also indicated that customer notices could include information such as dates of birth, addresses, phone numbers, passports, driving licences, verification selfies, account statements and transaction records.

For some customers, transaction information could include cryptocurrency activity.

That is especially sensitive because transaction histories can potentially provide criminals with information about a person's financial activity and, in some cases, their involvement with digital assets.

Why crypto users may face additional risks

The incident has attracted particular attention from the cryptocurrency community because some of the affected customers were reportedly selected based on their financial activity.

The Financial Times reported that the alleged attackers claimed to have targeted customers with significant cryptocurrency holdings.

If accurate, this could make the incident more concerning than a conventional identity-data leak.

A stolen passport or address can potentially be used for identity fraud. But when that information is combined with transaction history, account details and knowledge of cryptocurrency holdings, criminals may have a much clearer picture of a potential target.

That information could potentially be used for phishing, impersonation, financial fraud or highly targeted social-engineering attacks.

The blackmail claims add another layer

The latest reports suggest that the alleged attackers are not simply trying to sell a database.

People whose information was allegedly included in the stolen records may also face direct pressure.

This is where the reported incident moves into potential extortion and blackmail. If criminals possess identity documents, contact details or financial records, they may attempt to convince victims that paying money is the only way to prevent the information from being published.

Customers should be cautious about such threats.

The appearance of personal information in material published by an alleged hacker does not automatically prove that every piece of information is genuine. Cybercriminals can mix authentic, outdated or fabricated information into claims designed to increase pressure on victims.

Was Revolut's banking system hacked?

Based on Revolut's public statements, the incident was not described as a compromise of its core banking systems.

The company said an unauthorized third party obtained customer information through fraudulent requests originating from a legitimate government agency email domain. Reuters reported that Revolut characterized the event as an external impersonation scam.

This distinction is important.

A traditional cyberattack might involve criminals stealing credentials and directly accessing a company's database. In this case, the reported method involved convincing the company to provide information through a process that was supposed to be used for legitimate government requests.

In other words, the attackers allegedly abused trust rather than simply breaking through a technical firewall.

What information may have been exposed?

Reports about the incident indicate that affected customer information could include several categories of sensitive data.

These may include:

  • Names and dates of birth

  • Postal and email addresses

  • Telephone numbers

  • Passport and driving-licence information

  • Verification selfies

  • Account statements

  • IBAN and account information

  • Withdrawal records

  • Transaction histories

  • Cryptocurrency transaction information

The exact information exposed may vary from customer to customer. Revolut has reportedly been contacting affected individuals directly with information about the data associated with their particular case.

What Revolut customers should do now

Customers who receive an official notification from Revolut should take it seriously, but they should also be careful about follow-up messages.

A data breach can create an opportunity for criminals to launch convincing phishing campaigns.

For example, a scammer who knows a customer's name, phone number and recent financial activity may be able to make a fraudulent message appear much more credible.

Customers should therefore avoid sharing:

  • Passwords

  • One-time authentication codes

  • Recovery phrases

  • Private keys

  • Card security information

Anyone claiming to be from Revolut or law enforcement should not be trusted solely because they know information about the customer.

For cryptocurrency users, the most important rule remains unchanged: never share a wallet seed phrase or private key with anyone.

The investigation is still developing

Italian authorities are investigating aspects of the incident, while Revolut has said it is cooperating with law enforcement, regulators and relevant authorities.

The investigation will need to establish how the attackers were able to use a legitimate government communication channel, how the fraudulent requests passed through Revolut's verification process and exactly how much customer information was disclosed.

There is also a separate question surrounding the latest ransom website.

Authorities and cybersecurity researchers will need to determine whether the individuals behind the website actually possess all of the information they claim to have obtained and whether any of the material being advertised is genuine.

What happens next for Revolut?

The reported ransom campaign could put additional pressure on Revolut as it works with affected customers and authorities.

The company has already said that it blocked the fraudulent source after detecting the activity and took steps to notify the relevant organizations.

But the emergence of a public extortion website creates a new challenge.

If the alleged attackers begin releasing additional customer records, affected individuals could face increased risks of identity theft, phishing and targeted fraud.

For Revolut, the incident also highlights a broader cybersecurity problem facing financial institutions: protecting customer information is not only about defending internal networks. Companies must also ensure that sensitive data cannot be released simply because a request appears to originate from a trusted organization.

A warning for the wider crypto industry

The Revolut incident could have implications beyond one fintech company.

Cryptocurrency platforms, exchanges and financial institutions routinely hold a combination of identity documents, contact information and transaction records.

That makes them attractive targets for criminals who want to build detailed profiles of potential victims.

The reported Revolut attack shows why organizations need to independently verify sensitive information requests, even when those requests appear to originate from legitimate government or law-enforcement domains.

For customers, the lesson is equally important: a data breach does not necessarily end when the company blocks the original attacker.

The information obtained during an incident can potentially be used later for impersonation, phishing and financial fraud.

Bottom line

The latest Revolut development is a significant escalation of an already serious data-security incident.

A group claiming responsibility has reportedly launched a website advertising stolen customer information and demanded a $3 million ransom, while reports indicate that affected individuals may also be facing direct threats.

At the same time, Revolut has said it has not received a direct ransom demand from the alleged attackers, meaning the public extortion claims should remain clearly attributed until independently confirmed.

The investigation remains ongoing, and the full scope of the incident has yet to be established.

For affected customers, the immediate priority is to watch for suspicious communications, verify unexpected requests through official channels and never disclose passwords, authentication codes, private keys or cryptocurrency recovery phrases.

Post a Comment

0 Comments