Revolut data leak escalates into extortion as attackers threaten daily releases

Revolut data leak escalates into extortion as attackers threaten daily releases

N
News Editor
2026-09-14 12:22:56
Revolut is facing a more serious fallout from its recent data disclosure incident after attackers claiming to hold customer files said they are now extorting the company and may publish more records every day if payment is not made. City AM reported on Sept. 14 that a group calling itself "Revolut Smilik" confirmed it was demanding money from Revolut and issued the threat through Telegram. The development follows earlier reports that Revolut had been tricked by a fraudulent data request sent from an email account located within a real government domain, leading the company to hand over customer information to unauthorized parties. According to reporting cited in the source material, the exposed data may include passports or driver’s license copies, identity verification selfies, dates of birth, addresses, phone numbers, account statements, IBAN details, withdrawal records and full transaction histories, with some records potentially covering Bitcoin transactions. Revolut told Reuters that only a "very limited" number of customers were affected and said its systems and customer funds were not breached. The company has not disclosed how many users were impacted, whether it will respond to the extortion demand, the name of the government entity whose infrastructure was abused, or the amount of ransom being sought. The U.K. Information Commissioner’s Office said it has received a report and is assessing the material.

Revolut’s mistaken disclosure of customer data to unauthorized parties has moved into an extortion phase. City AM reported on Sept. 14 that a group calling itself "Revolut Smilik" said it is demanding payment from the fintech company and threatened on Telegram to release "more and more data, every day."

The case stems from what Revolut described as a "sophisticated external impersonation scam." Earlier reporting said the attackers sent a data request from an email account hosted within a real government domain, leading Revolut to treat the request as legitimate and hand over some customer identity documents, account records and even Bitcoin transaction records.

Some customer files have already been published

According to City AM, data tied to some public figures has already been exposed. Since Sept. 13, files said to be linked to several public individuals have circulated on X and Telegram.

Recently leaked material also indicates that the attackers have started publishing identity documents and verification photos they claim belong to affected customers. The group said it would keep releasing additional material each day if Revolut does not pay.

Revolut has not disclosed how many customers were affected and did not comment on whether it would respond to the extortion demand.

The exposed records go well beyond names and email addresses

Reuters, citing Revolut, said the incident affected only a "very limited" number of customers and that the company’s systems and customer funds were not compromised. Revolut said it blocked the relevant addresses after discovering the issue and notified government bodies, law enforcement, data protection authorities and financial regulators.

Customer notifications indicate the disclosed material is far more sensitive than basic contact data. The records may include dates of birth, home addresses, phone numbers, passport or driver’s license copies, identity verification selfies, account statements, IBAN details, withdrawal records and complete transaction histories. Some of that material may include Bitcoin transaction records.

The U.K. Information Commissioner’s Office, or ICO, confirmed to City AM that it had received a report from Revolut and is assessing the information.

Bitcoin transaction records raise additional concerns

The incident is especially sensitive for crypto users. If attackers hold a person’s real name, address, passport details and full Bitcoin transaction history at the same time, that data could be used to connect a real-world identity to specific crypto activity.

On-chain investigator ZachXBT had earlier suspected that the incident might involve the targeting of high-asset users. Revolut, however, has not released the number of affected users and has not confirmed whether the case is concentrated among high-net-worth customers.

That leaves the issue short of being definitively described as an attack on "crypto wealthy" users. Even so, if criminals obtain KYC records, residential address data and on-chain activity together, the resulting risk is plainly higher than in a standard email address leak.

Several key details remain undisclosed

As of the evening of Sept. 14, Revolut had not published the exact number of affected customers, had not named the government body whose infrastructure was impersonated, and had not confirmed the specific ransom amount being demanded.

What is clear so far is that the incident has escalated from an erroneous transfer of customer records into public extortion, and the attackers have already begun releasing data they claim to have obtained. Their statement that disclosures will increase "every day" remains a threat made by the attackers, and whether more files continue to appear remains to be seen.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
10300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.