Revolut data breach investigations widened after about 680 customers were identified as affected. UK regulators are reviewing the incident. An extortion group also threatened further releases of allegedly stolen customer records in the coming days, according to a report.
What happened in the Revolut data breach?
Revolut confirmed its data breach on Sept. 12, 2026. According to Reuters, Revolut explained that the company had received fraudulent requests from a third-party using a government body’s domain via emails. The requests were deemed authentic by the company.
Also Read: CoinEx Shutdown Begins as Exchange Announces December 22 Closure
Reuters mentioned that the messages had valid credentials to authenticate the domain. The requests were processed by the compliance team as legitimate until they discovered the impersonation. Revolut has termed this incident as a “sophisticated external impersonation scam.”
According to The Financial Times, Revolut informed 680 people of the problem found in its first phase of investigation. Revolut claims that the impacted customers form a “very limited number” of their clients. Revolut has not officially disclosed any number.
Who Was Affected by the Exposure?
The customer notices from several outlets contained personal information that may have been shared. The records contained the following: names, dates of birth, occupations, addresses, email addresses, and phone numbers. Identifiers were also mentioned in the customer notices.
Passports or drivers’ licenses may have been provided as part of the leaked data. The selfies taken to prove identity were included in the notices. Revolut stated that biometric facial telemetry information was not part of the information that may have been exposed.
Financial data may have been included in the following form: IBANs, the dates of account openings, account status, withdrawal information, and complete transaction history.
In case of the crypto customers, information about Bitcoin transactions and wallet reference numbers from account records may have been part of the records. Private keys were not mentioned in the notices.
The notices did not mention account passwords or full payment card details as exposed data. They listed categories of information that may have been disclosed. This does not mean every affected customer had all listed data exposed.
According to the Financial Times, former Mt. Gox CEO Mark Karpelès was among the affected customers. Karpelès said he received an email from Revolut at 5:25 a.m. on Sept. 12 warning that his data may have been compromised.
Why Did the Incident Trigger Regulatory Attention?
The regulator responsible for data protection in Britain has started an evaluation of the Revolut data breach. The Financial Conduct Authority will be talking with the London-based fintech firm. Their interest makes the issue more pressing for Revolut concerning handling of the requests.
Revolut claims to block the IP address once it detects the fraud. Afterward, the company reported the situation to the government agency concerned, law enforcement, data protection authorities, and financial regulators. According to a spokesperson, neither Revolut systems nor customer funds were affected.
Revolut’s public request page asks authorities and their representatives to use the court-order email address. They ask authorities to send one email per case. No information was provided by Revolut about what verification steps they did with the fraudulent requests.
Karpeles wondered why Revolut disclosed the data when the request came from a verified government address. This comment showed his perception of how Revolut handled the situation. However, no regulator announced its conclusion to support him.
On-chain investigator ZachXBT shared the message for customers regarding the Revolut data breach. According to ZachXBT, the breach was small in terms of its scale and probably targeted high-net-worth individuals only.
Where Did the Fraudulent Requests Come From?
Revolut Smilik, a threat actor group, took responsibility for the attack. This group demanded 10,000 Bitcoins and threatened to leak files on a daily basis. Revolut refused to inform Recorded Future News whether it received and responded to the extortion demand.
As per the Recorded Future News report, materials were distributed via a Telegram channel. A customer whose information was leaked in those materials did not refute their authenticity. A cryptocurrency entrepreneur, Marc Zeller, separately stated that his information had been revealed.
Some of the information provided by the attackers is still unconfirmed. The Telegram account indicated that the government email had originated from an Italian domain. According to Recorded Future News, it was not possible to verify all information posted in the Telegram channel.
Authorities in Italy that were contacted by the publication have not responded yet. This Telegram channel has been closed. Revolut has not revealed the government agency whose email server has been hacked.
No statement found as of Sept. 15 on how the account of the government agency was compromised. It is not clear whether stolen credentials or any other way was used. Nothing confirms that this access was exploited for targeting other financial companies.
The FBI earlier warned businesses about attacks from the criminals who managed to access the accounts of governments or law enforcement agencies. Then this email account was used to send emergency data requests. The message looks legitimate since it comes from the trusted domains.
Why Does the Revolut Data Breach Matter for UK Banking?
The Revolut data breach occurs several months after the firm had been granted permission to run its UK bank. The Prudential Regulation Authority granted permission for the Revolut Bank UK to run operations with the status of a bank. Deposits belonging to eligible customers were covered under the said arrangement.
Crypto transactions are not included in the said deposit insurance system. According to company data, Revolut services over 80 million customers across the world, as stated by TechCrunch and Recorded Future News. These 680 customers reflect the number ascertained through the investigation.
The figure should not be considered final unless Revolut or regulators release an updated total.
The firm claims to have contacted affected customers directly. The Revolut data breach remains under investigation as authorities examine the fraudulent information requests and resulting disclosures.
Also Read: CLARITY Act Faces Last-Minute Counterproposal Before Vote




Be the first to comment