Hackers Stole Revolut Customer Data Without Breaking Into Its Servers — Here’s How

A sophisticated impersonation scam allegedly tricked Revolut into handing over sensitive customer records. Now attackers are threatening to publish more data unless the fintech pays 10,000 Bitcoin.

A cyberattack against Revolut has taken an unusual and potentially damaging turn.

The fintech company confirmed on September 12 that an unauthorized party obtained sensitive customer information after fraudulent requests were submitted from an email account operating on the domain of a legitimate government agency. Revolut described the incident as a “sophisticated external impersonation scam.”

The incident has since escalated into an extortion attempt. Attackers claiming responsibility have reportedly begun publishing stolen customer records and are demanding 10,000 Bitcoin, an amount worth roughly $780 million at recent prices. Revolut has not publicly confirmed the ransom demand, so that figure should be treated as an allegation from the attackers rather than an established payment demand by the company.

The more troubling part of the story is that this was apparently not a conventional hack into Revolut’s banking infrastructure.

The attackers appear to have exploited something much more basic: trust in an apparently legitimate government communication.

Around 680 Revolut Customers Were Affected

The incident initially emerged without a confirmed number of affected customers.

By September 15, reporting citing sources close to the company indicated that approximately 680 customers had been affected. The affected customers are spread across multiple countries, including 12 in Ireland, 25 in Spain and 27 in Romania, according to reporting compiled from local sources.

That is a tiny fraction of Revolut’s more than 80 million customers globally.

But the number of victims isn’t the only issue.

The nature of the information involved makes this breach particularly serious.

Revolut has said affected customers were contacted directly, while regulators including the UK’s Information Commissioner’s Office have been notified. The ICO has confirmed that it is assessing the company’s report.

Revolut has also stressed that its core systems and customer funds were not compromised.

That distinction is important — but it doesn’t mean the exposed information is harmless.

What Data Was Exposed?

The information reportedly disclosed goes far beyond an ordinary email-address leak.

According to Revolut’s notification to affected customers and reporting based on the leaked material, the information potentially included:

  • Names
  • Dates of birth
  • Home and postal addresses
  • Email addresses
  • Phone numbers
  • Passport or driving-licence copies
  • Verification selfies
  • Occupations
  • IBAN information
  • Account statements
  • Withdrawal records
  • Transaction histories
  • Bitcoin transaction activity

That combination creates a particularly sensitive dataset.

A passport identifies a person.

A verification selfie can help establish that the person matches the identity document.

An address tells someone where that person lives.

And financial or cryptocurrency transaction information can reveal how that person uses their money.

The exposure of Bitcoin-related transaction information adds another dimension because blockchain transactions are publicly observable even though wallet addresses are generally pseudonymous. Linking blockchain activity to verified identity information can significantly reduce that practical anonymity.

The Hackers Didn’t Need to Break Into Revolut’s Servers

This may be the most important part of the entire incident.

The attackers apparently did not gain access by defeating Revolut’s banking systems.

Instead, they submitted fraudulent information requests that appeared to come from a legitimate government authority.

Revolut said the requests originated from an unauthorized email account operating within a genuine government agency’s domain infrastructure. Because the requests appeared authentic, the company processed them before later discovering that they were fraudulent.

That makes this a classic example of social engineering, but at a much more sophisticated level.

The attacker wasn’t necessarily trying to defeat the company’s technical defenses.

They were trying to convince the people operating those defenses that the request itself was legitimate.

How Could a Fake Request Look Real?

Modern email security systems can verify whether a message is authorized to use a particular domain.

Technologies such as:

  • SPF
  • DKIM
  • DMARC

help organizations determine whether emails are legitimately associated with a domain.

But there’s an important limitation.

A legitimate domain does not automatically mean a legitimate person is sending the request.

If an attacker obtains access to an email account belonging to a real government organization, a message can potentially originate from infrastructure that genuinely belongs to that organization.

That appears to be the weakness exploited in the Revolut incident.

Revolut reportedly believed the requests were genuine until it separately contacted the relevant government authority and discovered that the requests were fraudulent. The company then blocked the address and alerted authorities and regulators.

The Six-Month Claim Raises More Questions

The attackers have made additional claims about the incident.

According to reporting around the breach, the person or group claiming responsibility has alleged that the operation continued for months and that the attackers obtained a substantial amount of information.

Those claims should be treated cautiously.

The fact that customer information was disclosed has been acknowledged by Revolut. But claims made by an alleged attacker about the duration of an intrusion, the amount of data obtained or the full scope of the operation are not automatically verified simply because the attacker publishes them.

The Financial Times has reported that hackers claimed to have compromised an Italian government email system used for certified communications and then used it to obtain Revolut customer information. Italian authorities were investigating those claims.

The breach has moved from data exposure to extortion.

Attackers claiming responsibility have reportedly published customer records and threatened to release additional information unless Revolut pays 10,000 BTC.

At current Bitcoin prices, 10,000 BTC represents hundreds of millions of dollars. Reports have placed the demand around $780 million to $782 million.

But there is an important caveat:

Revolut has not confirmed the ransom demand.

The reported figure therefore shouldn’t be presented as an established fact about what Revolut has been formally asked to pay.

What is clearer is that attackers are claiming to possess customer information and are using the threat of additional publication as leverage.

That turns the incident into a potentially continuing privacy crisis rather than a breach that ended when the original fraudulent requests were discovered.

Why the Bitcoin Data Could Be Especially Sensitive

There is another unusual aspect to this incident.

Some of the exposed information reportedly includes Bitcoin transaction histories.

Bitcoin itself is not anonymous in the conventional sense. Its blockchain records transactions publicly. What makes the system pseudonymous is that blockchain addresses aren’t automatically connected to real-world identities.

But imagine combining:

Passport + selfie + address + bank information + Bitcoin transaction history

That creates a much more detailed profile.

Someone who can associate a person’s identity with cryptocurrency activity may have information useful for targeted phishing, impersonation, fraud or extortion.

This is why the combination of KYC information and transaction history can potentially be more consequential than either category of information by itself.

💡 Wisdom Imbibe Insight

The most revealing part of the Revolut breach isn’t the size of the ransom.

It’s how the attackers got the data in the first place.

For years, cybersecurity has largely been framed as a technological arms race:

  • Stronger encryption.
  • Better authentication.
  • More sophisticated firewalls.
  • More advanced fraud detection.

But this incident highlights a different problem.

What happens when the system correctly identifies the email as legitimate — but the person behind the email isn’t legitimate?

That is a much harder problem.

Technical authentication can establish that an email belongs to a real domain.

It cannot necessarily establish that the request itself is genuine.

And when the request involves highly sensitive information, that distinction becomes critical.

The lesson isn’t that email authentication is useless. It is that authentication and authorization are not the same thing.

A request can pass technical checks and still require independent human verification.

For financial institutions, governments and technology companies, that may become increasingly important as attackers learn to exploit trusted communication channels rather than attacking the underlying infrastructure directly.

The Bigger Cybersecurity Lesson: Trust Is Becoming an Attack Surface

Traditional hacking often means:

Break into the system → steal data.

Social engineering can work differently:

Become trusted → ask for the data → receive it legitimately.

That changes the defensive problem.

A company might have excellent network security and still expose sensitive information if an employee receives what appears to be an authentic legal or regulatory request.

The challenge becomes determining:

Who is actually authorized to make the request?

And perhaps more importantly:

How do you independently verify that authorization without creating another vulnerability?

That’s a difficult balance for financial companies because they also have legal obligations to respond to legitimate authorities.

Revolut Says Customer Funds Were Not Compromised

There is an important distinction between the customer-data incident and a direct compromise of Revolut’s banking infrastructure.

Revolut has said its systems and customer funds were unaffected. The incident involved information being disclosed to an unauthorized party following fraudulent requests.

That means this isn’t currently being described as a scenario in which hackers gained control of Revolut accounts and transferred customers’ money.

The immediate concern is instead the exposure and potential misuse of personal and financial information.

For affected customers, however, those risks can persist long after the original incident.

Regulators Are Now Looking Into the Incident

The UK’s Information Commissioner’s Office (ICO) has confirmed that it received a report from Revolut and is assessing the incident. The Financial Conduct Authority is also engaging with the company.

Those investigations could eventually provide answers to several important questions:

  • How were the fraudulent requests authenticated?
  • What internal verification procedures were followed?
  • Why was sensitive information released?
  • How long did the fraudulent requests continue?
  • How many records were actually obtained?
  • What safeguards have Revolut introduced?
  • Did the company’s procedures meet applicable regulatory requirements?

Those answers aren’t yet available.

This Wasn’t Just a Revolut Problem

Perhaps the biggest lesson from the incident extends beyond Revolut.

Banks, fintech companies, cryptocurrency exchanges, hospitals, insurers and other organizations routinely receive requests for information from government agencies, courts and law-enforcement bodies.

That makes trusted institutional communication itself an attack surface.

If criminals can compromise or impersonate an official communication channel, they may not need to attack the company’s core infrastructure at all.

They can potentially convince the company to do the work for them.

That’s a fundamentally different kind of cybersecurity problem.

What Happens Next?

The immediate questions are likely to center on three areas.

1. Will more customer information be published?

The attackers have reportedly threatened further releases. Whether the published records are all genuine, and how much additional information exists, remains under investigation.

2. How did the attackers obtain access to the government communication channel?

The Financial Times has reported claims involving an Italian government email system. Italian authorities are investigating the allegations.

3. Will Revolut change how it handles official requests?

The incident could force financial institutions to reconsider how they verify requests that appear to originate from government agencies.

That could mean additional independent verification before highly sensitive information is released.

The Real Danger May Not Be the $780 Million

A ransom demand of 10,000 Bitcoin makes an extraordinary headline.

But the more important story may be what happened before the ransom demand ever existed.

An attacker apparently found a way to make a fraudulent request look sufficiently legitimate that a major financial company disclosed sensitive information.

No vault had to be cracked.

No cryptocurrency wallet had to be drained.

No banking system necessarily had to be penetrated.

The attackers exploited trust.

And once passports, selfies, addresses and financial histories are outside the organization that was supposed to protect them, the consequences can continue long after the original attack has ended.

The Revolut case therefore illustrates an uncomfortable reality of modern cybersecurity:

Sometimes the easiest way to steal data isn’t to break through the security system — it’s to convince the security system to hand it over.

The reported 10,000-Bitcoin ransom remains unconfirmed by Revolut, but the underlying data disclosure and regulatory scrutiny are real. As investigations continue, the crucial question will be not only who obtained the information, but why the fraudulent requests were trusted in the first place.


Read Next

How to Protect Your Website From Unauthorized AI Agent Activity

As automated agents become more capable, website owners face a different version of the same security problem: determining whether a request is genuinely authorized before allowing access to sensitive information… read more

You May Also Like

Leave a Comment

All You Need to Know About Arjun Tendulkar’s Fiance. Neeraj Chopra’s Wife Himani Mor Quits Tennis, Rejects ₹1.5 Cr Job . Sip This Ancient Tea to Instantly Melt Stress Away! Fascinating and Lesser-Known Facts About Tea’s Rich Legacy. Natural Ayurvedic Drinks for Weight Loss and Radiant Skin .