• security
  • news
  • 43 min

Revolut Customer Data Leak: What Went Wrong and Who’s to Blame

Revolut is now in its fifth day of dealing with the fallout from an incident that technically wasn’t a hack: the neobank handed the data of hundreds of its own customers to fraudsters. Here’s how that turned into a public $3M ultimatum and a scandal on the eve

0

nft.eu
  • rating +26
  • subscribers 113

On September 12, 2026, British neobank Revolut, one of Europe’s most valuable fintechs, admitted that customer data had leaked. According to the Financial Times, around 680 people across dozens of countries were affected — passports, selfies, account details and transaction histories all got out. Overnight into September 17, a group of criminals posted a countdown timer on its own website and demanded 6,000 XMR (roughly $3M) within 24 hours, threatening to sell the customer data on to other criminal groups.

Sample of the leaked set: a passport page and a verification selfie. Source: the group’s website
Sample of the leaked set: a passport page and a verification selfie. Source: the group’s website

The company, for its part, still insists it has received no direct contact or demand from the extortionists.

The episode is a blow to Revolut’s reputation right before an IPO expected to value it at $200B. Tellingly, this is already the company’s second such incident: back in 2022 it disclosed a leak affecting 50,150 customers, the result of social engineering against an employee. That investigation was handled by Lithuania’s Data Protection Inspectorate, which oversees Revolut’s European banking license.

Timeline

For several months, the fraudsters corresponded with the company from an email address on a genuine domain belonging to Italy’s certified mail system PEC — a channel that carries the same legal weight as registered mail — while posing as law enforcement officers.

September 11–12. Revolut sent an official notification to the affected customers.

“Your data may have reached a third party as a result of an external impersonation scheme. The company’s infrastructure and customer funds were not affected,” the letter said.

A few hours before that announcement, on-chain investigator ZachXBT made the leak public. According to reporting by TechCrunch and Reuters, the company released dates of birth, addresses, phone numbers, copies of passports and driver’s licenses, and verification selfies. ZachXBT and the Financial Times add bank statements, IBANs and transaction histories to that list, including bitcoin activity.

September 13–14. The scammers, who call themselves IAmNotAVillain, started posting samples of the stolen documents on Telegram and on their own website. By their own account, they picked their targets through blockchain analysis, hunting for whales.

Among the published files were the details of tennis player Alexander Shevchenko, Gamdom crypto casino boss Felix Römer, and former Mt. Gox chief Mark Karpelès. Karpelès publicly criticized Revolut for releasing the data on the strength of an authenticated email alone.

Collage of stolen files. Source: International Cyber Digest on X
Collage of stolen files. Source: International Cyber Digest on X

September 15. Italy’s Polizia Postale confirmed an investigation into unauthorized access to the state-run PEC system. The UK’s ICO confirmed it had received notification of the incident and was assessing the information provided.

By September 16, the Financial Times counted around 680 affected customers in more than 30 countries, mostly in Switzerland and France. Revolut itself has not officially confirmed that number.

Revolut letter to Italy’s certified email and Swiss account confirmations. Source: International Cyber Digest on X
Revolut letter to Italy’s certified email and Swiss account confirmations. Source: International Cyber Digest on X

Overnight into September 17, things got worse. According to FT, the criminal group iamnotavillain issued a public ultimatum: about $3M in Monero (roughly 6,000 XMR) within 24 hours, or the data packages go on sale to other criminals.

Extortion and the countdown. Source: the ImNotAVillain group website
Extortion and the countdown. Source: the ImNotAVillain group website

An earlier demand for 10,000 BTC (~$780M) had circulated online from an account using a different name, but iamnotavillain said that was an impostor who had simply been handed a sample of the data.

Revolut has confirmed neither of the sums demanded. Nor has anyone independently confirmed the attackers’ own story about six months of access to several Italian law enforcement systems and the theft of 147 GB of internal data. Those details spread through niche Telegram and X channels, but the authorities have said nothing about them so far.

Views from the Industry

“The Revolut case fits badly into the usual categories of an insurance policy, because this was not a system breach but a release of data in response to a convincing yet fraudulent request,” said cyber insurer Cowbell.

Simon Hughes, chief commercial officer at Cowbell Cyber, noted that most successful attacks against their clients are built on the human factor.

Colin Parsons, head of anti-fraud strategy at Nasdaq Verafin, told PYMNTS even before the incident that most fraud schemes today play out beyond the bank’s own perimeter — inside institutions a bank is legally required to trust and has no way of checking.

Lyudmyla Kozlovska, president of the human rights organization Open Dialogue, believes Revolut had no choice.

“European regulation gives a bank no meaningful mechanism to verify who is actually behind a state request, and refusing to respond risks fines running into the millions,” she said.

And Efrat Fenigson, host of the podcast You’re The Voice and an independent journalist who writes about KYC among other things, is convinced that regulators keep pushing a model that is all but guaranteed to produce this outcome, even though technology that allows verification without storing data already exists.

“You can’t help but ask questions about that. It feels as though what’s missing here is both a rational approach and any real will to solve the problem,” she stressed.

Revolut Before the IPO: The Company’s Response and the Cost of the Incident

Revolut’s public channels are carrying on as if nothing had happened: social media is full of the usual stream of news about AI models, stablecoins and partnerships, while the company addresses the leak only in official comments to the press.

Formally, it points to the ongoing investigation, but customers are left with no clear sense of their own exposure. Reddit users complain that Revolut is disclosing neither the exact number of people affected nor which agency’s channel was compromised.

One person in the discussion claims to have lost around €50,000 in bitcoin and intends to sue the bank. (There is no independent confirmation that the funds were lost — editor’s note.)

The timing could hardly be worse. In July, a secondary share sale valued the company at $115B, and according to FT it is discussing an IPO target of $150–200B with investors — above the market capitalization of Barclays (~$85B), Deutsche Bank (~$73B) and Société Générale (~$62B).

In September, Revolut also received conditional OCC approval for a national banking license in the US and filed an application for a banking license in Switzerland. On September 17, founder Nik Storonsky confirmed in an interview with Les Echos that he is weighing a dual listing in New York and London and prefers the American market for its deeper liquidity; no decision or timeline has been locked in.

Since the company is still private, there is no direct share price reaction. What’s at stake is how regulators and institutional investors judge its operational discipline ahead of a listing. A second incident in four years moves the story out of the “one-off” category and into a conversation about a recurring pattern.

Editorial Conclusions and Forecast

What is happening to Revolut is objectively more dangerous than a classic account hack. The problem isn’t the loss of money but the security of KYC as a system: the volume of data collected, and the leaks that follow, hand criminals a full imprint of someone’s identity — and that can be more dangerous than direct access to their money.

Multiply a threat to user data by the capabilities of social engineering and deepfakes, and fraudsters end up holding ready-made material for bypassing biometric verification across a range of services and for targeted, personalized attacks on specific people rather than faceless phishing. Leaks like this one can do damage many times greater than the direct financial loss.

Then there is the company’s own response. What users are angry about is that Revolut is running the investigation as opaquely as possible, naming neither the scale nor the compromised channel. That strips customers of any sense of control over the chaos around them, and it undermines trust not only in one particular bank but in the fintech sector as a whole — a sector that is supposed to look secure enough to justify valuations in the hundreds of billions.

Our hypothesis: the number of victims will almost certainly be revised upwards, even though there is no public evidence of that yet — the same thing happened in 2022. An official decision from the ICO and the FCA is a matter of months. The ransom figure will most likely stay unconfirmed. It looks as though several competing extortionists are swarming around this leak, rather than one coordinated group.

Over the coming weeks, banks and rival neobanks will quietly tighten their checks on incoming “government” requests — callbacks, escalation for sensitive data — without waiting for regulators to order them to. For the IPO, the episode is unlikely to be a fatal barrier, since the company remains profitable, but it will certainly add to the questions and could push back the timing.

This post is for informational purposes only and does not constitute advertising or investment advice. Please do your own research before making any decisions.

0

Comments

0