Data Breach Overview
Revolut disclosed that a cyber‑attack resulted in the exposure of sensitive personal information belonging to approximately 680 (nearly 700) customers. The compromised data set included passport numbers, bank account details, residential addresses, verification photographs, identity cards and records of Bitcoin transactions.
Method of Attack
According to the report, the attackers employed a legitimate‑looking government email address to send a fraudulent request for private customer information. Revolut complied with the request and transmitted the data to the cyber‑criminals.
Threats and Ransom Demand
The hackers have claimed responsibility for the breach and are threatening to publish the obtained information publicly unless Revolut pays a ransom, although the amount of the ransom was not disclosed.
Regulatory Response
Britain’s Information Commissioner’s Office (ICO) announced on Monday that it is investigating the incident after Revolut reported the breach to the watchdog several days earlier. Revolut stated that it immediately blocked the offending email address after detecting the issue and subsequently notified regulators and the affected customers.
Customer Notification
At 5:25 a.m. on 12 September, Revolut sent an alert email to affected customers, including former Mt. Gox chief executive Mark Karpelès, warning that his data might be at risk. Karpelès publicly criticised the decision to share his information, arguing that Revolut should not have complied even though the email appeared to originate from a verified government source.
Impact
The breach highlights vulnerabilities in the verification of government‑originated communications and has prompted regulatory scrutiny of Revolut’s data‑handling procedures.