Digital banking platform Revolut suffered a data breach after falling victim to a sophisticated email impersonation scam that compromised sensitive information belonging to UK customers, according to reports from TechCrunch and Cybernews. The breach exposed identity documents, verification selfies, and full transaction histories, prompting threat actors to demand a 10,000 Bitcoin ransom.
How the Revolut Government Impersonation Scam Unfolded
According to statements provided to TechCrunch by Revolut, attackers utilized a legitimate government agency domain email to submit fraudulent requests for information. The threat actors either compromised or spoofed an email address belonging to authorities with statutory powers to demand customer records, tricking the fintech company into handing over a vast repository of private data.
Cybernews reported that the compromised files include customer birth dates, postal and email addresses, occupations, and phone numbers. Additional exposed records include copies of identity documents, account statements, IBANs, withdrawal records, and complete transaction histories, according to TechCrunch.
Ransom Demands and Telegram Data Leaks
Following the security breach, criminals began leaking stolen files on the messaging platform Telegram to pressure Revolut into paying a ransom, according to Coin Bureau. The threat actors demanded 10,000 BTC—valued at approximately $780 million—in exchange for deleting the stolen database.
Screenshots shared by Coin Bureau show the crooks leaking a verification selfie and full KYC documents belonging to the CEO of a crypto casino website. Muhammad Yahya Patel, vCISO and cybersecurity advisor at Huntress, told TechCrunch that the exposure constitutes a complete identity theft kit rather than a standard data breach.
“Every single component needed to impersonate someone, open accounts in their name, or bypass checks at other financial institutions is in that package,” Patel said, noting that such complete profiles command a significant premium on the dark web.
Revolut Response and Regulatory Notifications
Revolut stated that upon detecting the breach, it immediately blocked the offending email address and alerted the relevant government agency, law enforcement, data protection authorities, and financial regulators, according to a company spokesperson who spoke with Reuters.

While Revolut has not disclosed the exact total of impacted individuals, the company told Reuters that only a “very limited” number of customers were affected and that all of them had already received notifications regarding the incident.