Hackers demand a Bitcoin ransom from Revolut, threaten to publish customer and internal data
Attackers say they have information on Revolut customers and internal operations, and they are using screenshots and selective data drops to pressure the company into paying. For PSPs and fintech operators, the detail that matters is not the theatrics; it is the data set in play: account records, IBANs, identity documents, and transaction history.
- According to the screenshots shared in Telegram, the attackers demanded payment in Bitcoin and threatened to release stolen customer information if Revolut refused to pay. They also claimed they would publish more messages, data, and details about how the Revolut team operates.
- The attackers accused Revolut of negligence and of sending personal data to countries whose laws do not apply to the company’s UK entity. In the same screenshots, they showed data allegedly tied to tennis player Alexander Shevchenko and Felix Römer, CEO of online casino Gamdom, and wrote that “Revolut is waiting for collapse.”
- Last week, the attackers sent Revolut a request from a fake address masked as an unnamed government domain, asking for confidential customer data and Bitcoin transaction history. The set of data they are believed to have accessed includes transaction history, account statements, IBANs, selfie verification images, identity document images, phone numbers, and home addresses.
- Revolut said the incident affected a limited number of customers. The company blacklisted the attackers’ address and notified law enforcement and affected users. Anonymous blockchain investigator ZachXBT suggested the attackers were primarily targeting wealthy Revolut customers.
- The breach landed at an awkward time for Revolut: the company had been preparing for an IPO with a targeted market capitalization of $200 billion.
For high-risk merchants, the operational takeaway is straightforward: when a fintech platform holds KYC files, IBANs, and transaction histories, a data breach is not just a privacy event. It becomes a counterparty-risk event, a fraud risk event, and a treasury-risk event all at once.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!