Attackers who impersonated a government agency to access Revolut customer records have published data belonging to high-profile clients and demanded a ransom of 10,000 Bitcoin. The group, calling itself Revolut Smilik, posted the material across multiple Telegram channels on September 14, warning they would release additional data daily until the European fintech complies with their demand.
Revolut confirmed on September 12 that an unauthorized party had impersonated a government agency, using an email address on the agency's legitimate domain with valid technical authentication. The fraudulent requests were processed by staff as routine legal inquiries.
Scope of Data Breach
The compromised data included passports, verification selfies, account statements, IBANs, names, dates of birth, and home addresses. The leaked information also encompassed full Bitcoin transaction histories for some customers. Revolut confirmed that biometric facial data was not compromised.
Among the individuals whose data was published were tennis player Alexander Shevchenko and Gamdom CEO Felix Römer. The leaked material appeared to focus on high-profile individuals including company executives, sports professionals, and performing artists.
Company Response
Upon detection of the breach, Revolut blocked the fraudulent address and alerted relevant government agencies, law enforcement, data protection authorities, and financial regulators. The company stated that its systems and customer funds remained unaffected and that a limited number of customers were impacted, though it did not disclose specific figures or identify the compromised agency.
Revolut declined to comment on the ransom demand. The company contacted affected customers directly but has not publicly disclosed the total number of individuals impacted.
Potential Risks
The theft of customer records poses heightened phishing risks, particularly for cryptocurrency holders. Previous breaches of crypto platforms have resulted in targeted scams exploiting leaked personal and financial information. Similar incidents have enabled criminals to craft convincing fraudulent communications designed to compromise account security.


