Industry News

Revolut Breach: Hackers Impersonating Government Agency Leak Customer Data, Demand Huge Ransom

CryptoPotato · 15 Sept 2026
Key Takeaway Even requests that appear to come from a verified government or official domain should be independently confirmed through a separate channel before sensitive customer data is released.

Fintech company Revolut has confirmed a data breach after attackers impersonated a government agency using a legitimate-looking domain email with valid technical authentication. Staff processed the fraudulent request as routine, allowing the attackers to obtain sensitive customer information including passports, verification selfies, account statements, IBANs, names, dates of birth and home addresses.

A group calling itself Revolut Smilik has since published some of this data on Telegram, including details on high-profile individuals such as company executives, athletes and performers. The group is demanding a ransom of 10,000 Bitcoin, reportedly worth hundreds of millions of dollars, and has threatened to release more data daily until it is paid. Revolut has declined to comment on the ransom demand.

Revolut said it blocked the malicious email address once identified, notified law enforcement, data protection authorities and financial regulators, and confirmed that customer funds and biometric facial data were not compromised. The company says a limited number of customers were affected and have been contacted directly, though it has not disclosed how many or named the impersonated agency.

data breach phishing impersonation attack fintech security ransom demand

Summarised by CISO AI from CryptoPotato. We link back to every original so you can read it yourself.