Revolut Battles Extortion After Major Data Breach
September 17, 2026, 9:32 pm

Location: United Kingdom, England, London
Employees: 1001-5000
Founded date: 2013

Location: United Kingdom, England, Wilmslow
Employees: 201-500
Founded date: 1984
Revolut has suffered a critical data breach. Nearly 700 customers had their private data stolen. Identity documents, personal addresses, facial verification images, phone numbers, and transaction histories are compromised. Hackers exploited a sophisticated impersonation scam. They used a fake government agency email to trick Revolut. The group, "Revolut Smilik," now demands extortion payment. They threaten to release more sensitive information daily if Revolut refuses. Regulatory bodies, including the FCA and ICO, are actively investigating the incident. Revolut maintains its core banking systems and infrastructure remain secure. This event underscores the escalating cybersecurity risks in digital finance. It highlights the constant threat to user privacy.
Digital banking giant Revolut faces a severe cybersecurity crisis. A recent data breach exposed sensitive customer information. Hackers leveraged a sophisticated impersonation scam. They tricked the fintech firm. Nearly 700 customers are affected. This incident sends shockwaves through the financial technology sector. It highlights the persistent threats to online security.
The breach involved a cunning deception. Attackers used an email from a legitimate government agency. This enabled them to submit fraudulent information requests. Revolut, like many financial institutions, processes such demands. This protocol allowed unauthorized access. Customer data was then siphoned off.
The hacker group identifies itself as "Revolut Smilik." They claim responsibility for the attack. This group has a clear demand. They seek a substantial payment from Revolut. Failure to comply carries a threat. More stolen customer data will be released daily. This escalates the crisis to an extortion attempt.
Compromised data includes highly sensitive details. Customers' identity documents were stolen. Postal and email addresses are exposed. Facial verification images are now in hacker hands. Phone numbers are also part of the loot. In some cases, full transaction histories are gone. Account statements and withdrawal records are also compromised. This puts individuals at high risk. Identity theft is a major concern.
Revolut has acted quickly. The company detected the fraudulent activity. They immediately blocked the rogue address. Relevant authorities were alerted. Government agencies received notifications. Law enforcement, data protection, and financial regulators are now involved. This response aims to mitigate damage. It seeks to prevent further leaks.
Despite the breach, Revolut offers reassurance. The company states its core infrastructure remains secure. Databases were not compromised directly. Customer accounts are reportedly safe. This distinction is crucial. It suggests the breach was limited to specific data requests. It did not penetrate the entire system.
Regulators are watching closely. The Financial Conduct Authority (FCA) is engaged. They assess the impact. They examine Revolut's mitigation steps. The Information Commissioner’s Office (ICO) also confirms a report. Both agencies are scrutinizing the situation. They will ensure compliance and accountability.
This incident underscores a broader trend. Digital attacks on companies are increasing. They pose a significant threat. Cybersecurity is a top priority for all enterprises. Fintech companies, handling vast amounts of sensitive data, are prime targets. The cost of such breaches can be immense.
Revolut is a global powerhouse. It serves over 80 million customers. Operations span more than 30 countries. The company has secured numerous licenses. Approvals from regulators across continents underscore its reach. This extensive network makes the breach more impactful. Trust is paramount in digital banking.
The stolen data could enable sophisticated fraud. Phishing attacks become more plausible. Identity theft risks skyrocket. Customers must remain vigilant. They should monitor their accounts. They must report any suspicious activity immediately. Companies must also enhance their defenses.
Cybersecurity investments are critical. Financial institutions must continuously adapt. New threats emerge constantly. Sophisticated scams require sophisticated countermeasures. Employee training is essential. Robust verification protocols are non-negotiable. Protecting customer data is paramount.
Revolut has not confirmed direct contact with the hackers. The extortion demands persist. Data releases targeting "notable figures" have reportedly occurred. This adds urgency to the situation. It puts pressure on the company. A delicate negotiation may unfold.
This event serves as a stark reminder. No system is entirely impervious to attack. Even established fintech giants face vulnerabilities. The digital landscape demands constant vigilance. Both companies and users must prioritize security. The battle against cybercrime is ongoing.
The integrity of digital finance relies on trust. Data breaches erode that trust. Companies must rebuild it. They must demonstrate strong security postures. Transparency with affected customers is vital. Comprehensive protection strategies are now a baseline expectation. The financial industry watches closely. Revolut's response will set precedents.
Digital banking giant Revolut faces a severe cybersecurity crisis. A recent data breach exposed sensitive customer information. Hackers leveraged a sophisticated impersonation scam. They tricked the fintech firm. Nearly 700 customers are affected. This incident sends shockwaves through the financial technology sector. It highlights the persistent threats to online security.
The breach involved a cunning deception. Attackers used an email from a legitimate government agency. This enabled them to submit fraudulent information requests. Revolut, like many financial institutions, processes such demands. This protocol allowed unauthorized access. Customer data was then siphoned off.
The hacker group identifies itself as "Revolut Smilik." They claim responsibility for the attack. This group has a clear demand. They seek a substantial payment from Revolut. Failure to comply carries a threat. More stolen customer data will be released daily. This escalates the crisis to an extortion attempt.
Compromised data includes highly sensitive details. Customers' identity documents were stolen. Postal and email addresses are exposed. Facial verification images are now in hacker hands. Phone numbers are also part of the loot. In some cases, full transaction histories are gone. Account statements and withdrawal records are also compromised. This puts individuals at high risk. Identity theft is a major concern.
Revolut has acted quickly. The company detected the fraudulent activity. They immediately blocked the rogue address. Relevant authorities were alerted. Government agencies received notifications. Law enforcement, data protection, and financial regulators are now involved. This response aims to mitigate damage. It seeks to prevent further leaks.
Despite the breach, Revolut offers reassurance. The company states its core infrastructure remains secure. Databases were not compromised directly. Customer accounts are reportedly safe. This distinction is crucial. It suggests the breach was limited to specific data requests. It did not penetrate the entire system.
Regulators are watching closely. The Financial Conduct Authority (FCA) is engaged. They assess the impact. They examine Revolut's mitigation steps. The Information Commissioner’s Office (ICO) also confirms a report. Both agencies are scrutinizing the situation. They will ensure compliance and accountability.
This incident underscores a broader trend. Digital attacks on companies are increasing. They pose a significant threat. Cybersecurity is a top priority for all enterprises. Fintech companies, handling vast amounts of sensitive data, are prime targets. The cost of such breaches can be immense.
Revolut is a global powerhouse. It serves over 80 million customers. Operations span more than 30 countries. The company has secured numerous licenses. Approvals from regulators across continents underscore its reach. This extensive network makes the breach more impactful. Trust is paramount in digital banking.
The stolen data could enable sophisticated fraud. Phishing attacks become more plausible. Identity theft risks skyrocket. Customers must remain vigilant. They should monitor their accounts. They must report any suspicious activity immediately. Companies must also enhance their defenses.
Cybersecurity investments are critical. Financial institutions must continuously adapt. New threats emerge constantly. Sophisticated scams require sophisticated countermeasures. Employee training is essential. Robust verification protocols are non-negotiable. Protecting customer data is paramount.
Revolut has not confirmed direct contact with the hackers. The extortion demands persist. Data releases targeting "notable figures" have reportedly occurred. This adds urgency to the situation. It puts pressure on the company. A delicate negotiation may unfold.
This event serves as a stark reminder. No system is entirely impervious to attack. Even established fintech giants face vulnerabilities. The digital landscape demands constant vigilance. Both companies and users must prioritize security. The battle against cybercrime is ongoing.
The integrity of digital finance relies on trust. Data breaches erode that trust. Companies must rebuild it. They must demonstrate strong security postures. Transparency with affected customers is vital. Comprehensive protection strategies are now a baseline expectation. The financial industry watches closely. Revolut's response will set precedents.
