Attackers who exploited a fraudulent government request to access Revolut customer records have published the personal data of high-profile clients and demanded a ransom of 10,000 Bitcoin (over $782 million). The group, calling itself Revolut Smilik, warned it would release more data daily until the fintech pays. Revolut confirmed on September 12 that an unauthorized party impersonated a government agency using a real domain email with valid authentication. The company blocked the address, alerted regulators and law enforcement, and stated that systems and customer funds remain unaffected. A limited number of customers were affected, and the company has contacted them directly.
Attackers who tricked Revolut into handing over customer records published the data of high-profile clients over the weekend and demanded a ransom of 10,000 Bitcoin, warning on September 14 that they would leak more each day until the European fintech pays. Revolut confirmed on September 12 that an unauthorized party had impersonated a government agency, sending fraudulent requests for information from an email on the agency’s real domain with valid technical authentication, which staff processed as a routine legal request.
As CryptoPotato covered, the data breach included the disclosure of passports, verification selfies, account statements and IBANs, alongside names, dates of birth and home addresses. A Revolut spokesperson said the company “recently identified a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information.”
The group calling itself Revolut Smilik posted client files across several Telegram channels and warned it would “start releasing more and more data every day until Revolut pays for leaking their customers.” The posted material appeared to include data on high-profile individuals, including company executives, sports professionals, and performing artists, according to The Register, which put the 10,000 Bitcoin demand at more than $782 million.
Revolut said it blocked the address on detection and alerted the relevant government agency, law enforcement, data protection and financial regulators, and that its systems and customer funds were unaffected. The company said a limited number of customers were affected and that it had contacted them directly, without disclosing a figure or naming the compromised agency.
The company had earlier said the affected customers’ biometric facial data was not compromised. On-chain investigator ZachXBT, who flagged the incident, said it appeared limited in size and concentrated on high-net-worth users, an assessment neither Revolut nor independent parties have confirmed.
Revolut lets customers buy and sell more than 90 cryptocurrencies, and the stolen files included some clients’ full Bitcoin transaction histories. Similar leaks have fed targeted scams against crypto holders, as CryptoPotato documented how criminals used leaked order data to send Ledger owners convincing phishing emails after a separate breach.
The Revolut demand follows a pattern of ransomware attacks targeting crypto firms, similar to Coinbase, where a ransom demand forced the exchange to disclose a breach affecting more than 69,000 customers after overseas support agents were bribed to hand over their records.
