Revolut faces ransom demands over customer data

The “Revolut scam” is not one single crime. It is a pattern: criminals impersonate banks, support teams, or even governments, then trick either customers or Revolut itself into handing over money or data. The latest version is especially striking because Revolut was the one that got fooled.
Watch this fascinating insight by CITY AM.
In September 2026, Revolut confirmed it had disclosed sensitive customer information after receiving fraudulent information requests from an email address on a real government agency domain. techcrunch.com
This was not a hack of Revolut’s app or core systems. Staff treated the emails as legitimate legal or compliance requests because they arrived through official-looking government infrastructure and passed technical authentication. Revolut later blocked the address, notified the agency, and alerted law enforcement and regulators. It says customer funds and its own systems were unaffected.
Reports and customer notices describe the exposed data as including:
names, dates of birth, addresses, emails, phone numbers
copies of passports or driving licences
verification selfies
account statements, IBANs, withdrawal records, and transaction histories, including Bitcoin activity in some cases
Revolut has called the number of affected customers “limited.” Later reporting put the figure around 680 people, including high-profile crypto users. Attackers then circulated data on Telegram and demanded a large Bitcoin ransom.
That is the current “Revolut scam” in the headlines: social engineering aimed at the company, not a breach of its servers.




Comments