Decoding the world of cybersecurity

· ·

Revolut breach shifts into alleged extortion

Attackers claiming responsibility for Revolut’s customer-data breach have reportedly demanded $3 million, while the fintech says it has received no direct contact or ransom demand.

Revolut breach shifts into alleged extortion
Summary
  • A group claiming responsibility has reportedly threatened to sell records unless Revolut pays a $3m ransom.
  • Revolut says it has received no direct contact or demand from the purported attackers.
  • The claim follows confirmed disclosure of sensitive customer information through fraudulent government requests.

The customer-data incident at Revolut has developed into an alleged extortion attempt, with a group claiming responsibility reportedly demanding $3 million while the fintech says it has received no direct contact or ransom demand.

The Financial Times reported that the group threatened to sell confidential records belonging to hundreds of customers to other criminal groups unless Revolut paid within 24 hours. Reuters subsequently obtained a statement from Revolut saying the company had received no direct demand or communication from the purported attackers.

The extortion claim therefore remains an allegation made publicly by the group rather than evidence of an established negotiation between Revolut and those claiming to hold the data.

Reuters reported that the breach is understood to have affected around 680 customers, citing a source familiar with the matter. Revolut itself has described the affected population as a very limited number without publishing an exact figure.

The incident began when fraudulent government requests caused customer information to be disclosed. Revolut confirmed that the requests arrived from a legitimate government-agency email domain, increasing their apparent credibility.

The company says its systems and customer funds were unaffected. A source familiar with the incident also told Reuters that Revolut’s core infrastructure, databases, and customer accounts were not hacked.

That makes the event a process and trust failure rather than evidence that attackers penetrated the bank’s primary technology environment. Sensitive information was released because fraudulent external requests were treated as legitimate.

Revolut has not publicly provided a full inventory of data exposed. Reuters reported separately, citing TechCrunch, that affected information included dates of birth, postal and email addresses, phone numbers, and copies of identity documents such as passports and driving licences.

The reported extortion phase raises the prospect of that information being distributed more widely without establishing that the group possesses every record it claims. Public criminal claims about dataset size, completeness, or onward sale require caution even where some genuine information has already been demonstrated.

The case also exposes a difficult control point around lawful information requests. Banks and technology companies need mechanisms for responding to police, courts, regulators, and other authorities, and those processes can involve disclosure without the customer authenticating the request themselves.

When a request comes from a compromised or otherwise legitimate government communications channel, conventional checks on the sender domain can be insufficient. The decision instead depends on validating the authority, provenance, case information, and independent authenticity of the request.

The consequences of a failure can persist beyond the initial incident. Identity documents, addresses, contact information, and financial records can retain value for fraud, impersonation, phishing, and other targeted criminal activity even after the route used to obtain them has been closed.

Revolut said after discovering the original disclosure that it blocked the relevant address and notified the government agency, law enforcement, data-protection authorities, and financial regulators.

Whether the public $3 million demand leads to further disclosure remains unresolved. What is confirmed is that sensitive information left Revolut through fraudulent requests; the identity and full holdings of the group now claiming responsibility, and whether it will distribute additional records, remain less certain.

×