< Back to all clusters
[TECHNOLOGY] · United Kingdom, Italy, Spain, France, Ireland · 18 sources

started · updated

Revolut confirms data exposure via government impersonation scam

Fintech company Revolut has confirmed a security incident involving the exposure of sensitive customer data. The breach was not a technical system hack but a sophisticated social engineering attack. Attackers used a legitimate government agency email domain to submit fraudulent requests for information, which Revolut processed as authentic.

The exposed data reportedly includes full names, dates of birth, contact details, and identity documents such as passports and driver’s licenses, as well as verification selfies. Financial information, including IBANs, account statements, and Bitcoin transaction histories, was also compromised. Some reports suggest the attack specifically targeted high-net-worth individuals.

A group identifying as Revolut Smilik has reportedly claimed responsibility on Telegram, demanding a ransom of 10,000 Bitcoin, valued at approximately $780 million, to halt further data leaks. Revolut stated that its internal systems and customer funds remain unaffected. The company has notified law enforcement, financial regulators, and data protection authorities.

Entities

Alexander Shevchenko · Felix Römer · Gamdom · Revolut · ZachXBT

Claims

What the coverage asserts, and how many sources carry each claim.

Sources

about 8 hours ago
about 8 hours ago