< Back to situation

[REVISION HISTORY]

Revolut customer data disclosure via impersonation scam

Updated 3 times since CLSTR started tracking revisions of this situation.

What changed

2026-09-14 16:03 UTC → 2026-09-14 17:26 UTC · added removed

Fintech company Revolut has confirmed a data disclosure incident resulting from a sophisticated impersonation scam. Rather than a direct breach of its technical infrastructure, unauthorized third parties used a legitimate government agency email domain with valid authentication credentials to submit fraudulent requests for customer information. This method allowed the requests to bypass automated security checks. The disclosed sensitive data includes full names, dates of birth, postal and email addresses, phone numbers, IBANs, and account statements. In several instances, the breach also involved copies of identity documents such as passports, driver’s licenses, and verification selfies. Transaction histories, including Bitcoin activity, were also exposed. While Revolut maintains that its core technical systems and customer funds remain secure, new reports indicate the incident may have specifically targeted high-net-worth individuals. On-chain investigator ZachXBT suggested the attackers may be seeking a ransom, and there are reports that hackers have begun sharing some of the stolen data on Telegram. Recent developments indicate the scale of the extortion attempt, with one report suggesting attackers have demanded 10,000 Bitcoin, valued at approximately $780 million. To prove the breach, hackers have reportedly shared the data of high-profile individuals, including tennis player Alexander Shevchenko and Gamdom CEO Felix Römer. A group identifying as ‘Revolut Smilik’ has reportedly claimed responsibility for the incident on Telegram, demanding the ransom to halt further leaks. Revolut has blocked the fraudulent email source and has notified law enforcement, financial regulators, the relevant government agency, and the impacted individuals. Experts continue to warn that the stolen information could facilitate highly targeted phishing and identity theft attempts.

Versions

  1. 2026-09-14 17:26 UTC Revolut customer data disclosure via impersonation scam
  2. 2026-09-14 16:03 UTC Revolut customer data disclosure via impersonation scam
  3. 2026-09-14 11:03 UTC Revolut customer data disclosure via impersonation scam
  4. 2026-09-14 09:12 UTC Revolut customer data disclosure via impersonation scam

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.