Revolut Faces $3m Ransom Demand After Customer Data Breach
Revolut is facing a $3 million ransom demand after a cyberattack compromised the personal records of hundreds of European customers.
The incident exposes critical vulnerabilities in external identity verification pipelines. Rather than breaching Revolut’s core proprietary infrastructure directly, the attackers compromised an Italian government email system. By exploiting this third-party channel, the criminals impersonated law enforcement officials over several months to extract sensitive customer verification files. This vector highlights the cascading risks financial institutions face when third-party public sector nodes are leveraged for Know Your Customer (KYC) data exchanges.
The threat actors utilized blockchain analysis to isolate high-value targets, specifically focusing on Revolut accounts holding substantial cryptocurrency balances. The stolen data includes government-issued identification documents such as passports and driving licences, verification photographs, and detailed transaction histories.
The public nature of the extortion attempt marks a departure from standard cybercriminal methodology. As detailed by The Financial Times, threat actors typically conduct ransom negotiations privately, resorting to public leak sites only after direct communication stalls. In this instance, the group launched a dedicated website featuring a digital countdown clock and a 60-second screen-capture video displaying the compromised documents to journalists.
Corporate resilience hinges on rapid remediation and third-party risk assessment.
Revolut stated that it had not received any direct communication or ransom demands from the individuals or groups orchestrating the public shakedown. The fintech firm, which achieved a valuation of $115 billion in a recent secondary share sale and serves approximately 80 million customers across 30 countries, maintains that it is providing immediate support to affected clients while cooperating with regulatory authorities.