Revolut’s mistaken disclosure of customer data to unauthorized parties has moved into an extortion phase. City AM reported on Sept. 14 that a group calling itself "Revolut Smilik" said it is demanding payment from the fintech company and threatened on Telegram to release "more and more data, every day."
The case stems from what Revolut described as a "sophisticated external impersonation scam." Earlier reporting said the attackers sent a data request from an email account hosted within a real government domain, leading Revolut to treat the request as legitimate and hand over some customer identity documents, account records and even Bitcoin transaction records.
Some customer files have already been published
According to City AM, data tied to some public figures has already been exposed. Since Sept. 13, files said to be linked to several public individuals have circulated on X and Telegram.
Recently leaked material also indicates that the attackers have started publishing identity documents and verification photos they claim belong to affected customers. The group said it would keep releasing additional material each day if Revolut does not pay.
Revolut has not disclosed how many customers were affected and did not comment on whether it would respond to the extortion demand.
The exposed records go well beyond names and email addresses
Reuters, citing Revolut, said the incident affected only a "very limited" number of customers and that the company’s systems and customer funds were not compromised. Revolut said it blocked the relevant addresses after discovering the issue and notified government bodies, law enforcement, data protection authorities and financial regulators.
Customer notifications indicate the disclosed material is far more sensitive than basic contact data. The records may include dates of birth, home addresses, phone numbers, passport or driver’s license copies, identity verification selfies, account statements, IBAN details, withdrawal records and complete transaction histories. Some of that material may include Bitcoin transaction records.
The U.K. Information Commissioner’s Office, or ICO, confirmed to City AM that it had received a report from Revolut and is assessing the information.
Bitcoin transaction records raise additional concerns
The incident is especially sensitive for crypto users. If attackers hold a person’s real name, address, passport details and full Bitcoin transaction history at the same time, that data could be used to connect a real-world identity to specific crypto activity.
On-chain investigator ZachXBT had earlier suspected that the incident might involve the targeting of high-asset users. Revolut, however, has not released the number of affected users and has not confirmed whether the case is concentrated among high-net-worth customers.
That leaves the issue short of being definitively described as an attack on "crypto wealthy" users. Even so, if criminals obtain KYC records, residential address data and on-chain activity together, the resulting risk is plainly higher than in a standard email address leak.
Several key details remain undisclosed
As of the evening of Sept. 14, Revolut had not published the exact number of affected customers, had not named the government body whose infrastructure was impersonated, and had not confirmed the specific ransom amount being demanded.
What is clear so far is that the incident has escalated from an erroneous transfer of customer records into public extortion, and the attackers have already begun releasing data they claim to have obtained. Their statement that disclosures will increase "every day" remains a threat made by the attackers, and whether more files continue to appear remains to be seen.

