Revolut has confirmed that approximately 680 customers were affected in the customer-data disclosure incident it first acknowledged on 12 September 2026, moving the case from a vaguely described “limited” impact to a counted, multi-country event with active regulatory scrutiny.
Britain’s data-protection regulator has opened an assessment, the Financial Conduct Authority is engaging with the London-based fintech, and a threat-actor group calling itself Revolut Smilik is demanding a ransom of 10,000 Bitcoin (BTC) while threatening to release stolen files daily.
The 680 figure was first reported by the Financial Times, which described the group as “nearly 700.” A source close to the bank confirmed the number to City AM, which said Revolut had contacted all affected customers directly. The 680 total represents roughly 0.00085% of Revolut’s more than 80 million global customers. National breakdowns published on 15 September have begun to fill in the geographic map: 12 customers in Ireland, against a local base of about 3.4 million, according to RTÉ; 25 in Spain, according to El Español; and 27 in Romania, according to Profit.ro.
Those slices are small as a share of Revolut’s book, which spans 30 countries, but the composition of the leaked package is what makes the case unusual. The Crypto Times first reported on 12 September that fintech accepted fraudulent information requests sent from an authenticated government mailbox, and tracked the leak-and-extortion phase on 14 September. The new details on 15 September are the confirmed customer count, the national breakdown, and the regulatory response.
What Revolut Has Confirmed
Revolut told Reuters on 12 September that it identified a “sophisticated external impersonation scam” in which an unauthorized third party used a mailbox on a legitimate government agency domain to submit fraudulent information requests. The messages carried valid domain-authentication credentials, so Revolut’s compliance team treated them as genuine legal demands.
The company said it blocked the address after detection and alerted the impersonated agency, law enforcement, data-protection authorities and financial regulators. Revolut has repeatedly stressed that its systems, databases and customer funds were not compromised.
The customer notice, first circulated on 11 September 2026, lists four categories of possible disclosure: identity fields (name, date of birth, occupation); contact details (postal address, email, phone number); Know Your Customer (KYC) documents, including passport or driving-licence copies plus the onboarding verification selfie; and financial records, including account statements, International Bank Account Numbers (IBAN), withdrawal records and full transaction histories, including Bitcoin activity. Revolut said the biometric facial-recognition telemetry used to match selfies to identity documents was not shared.
UK Regulators Enter the File
An Information Commissioner’s Office (ICO) spokesperson told City AM: “We can confirm we have received a report and are assessing the information provided.” An assessment is not a finding of a breach under the UK General Data Protection Regulation (GDPR), but it opens the legal-request pipeline, not only the email filter, to review.
A Financial Conduct Authority (FCA) spokesperson added: “We are aware of the reported incident involving Revolut and are engaging with the firm to understand the impact and the steps being taken to address any potential harm.”
Revolut’s European banking licence sits with Revolut Bank UAB in Lithuania, supervised by the European Central Bank (ECB) and the Bank of Lithuania. The legal-request desk in Vilnius, rather than any consumer-facing app, is the operational point at which the disclosure occurred.
Extortion Track and Named Individuals
A group calling itself Revolut Smilik has begun publishing identity documents and verification selfies on public channels, and said in messages on Monday that it would release “more and more data everyday” until Revolut paid. The demand stands at 10,000 BTC, according to The Register. Revolut has not confirmed ransom talks, and City AM said the two sides have not been in direct contact.
Former Mt. Gox chief executive Mark Karpelès publicly confirmed receiving a notice on 12 September and posted excerpts from it. On-chain investigator ZachXBT, who flagged the notices to a wider audience the same day, assessed the targeting as concentrated on high-net-worth users rather than a mass retail dump.
Additional names circulating in threat-actor posts, including a tennis player identified as Shevchenko and Felix Römer, remain actor-attributed unless independently confirmed by the individuals or a matching customer notice.
Italian Domain Angle Remains Unverified
The identity of the impersonated agency has not been disclosed by Revolut. Recorded Future News wrote that extortion material circulated on Telegram pointed to an Italian domain and that Italian authorities it contacted did not respond to requests for comment.
The Telegram account has since been suspended. Broader claims about months-long use of Italian official mail and European Investigation Order (EIO) paperwork aimed at Revolut Bank UAB remain unverified and should be treated as leads rather than facts.
What Is Still Open
The 680 figure is a customer-notification count, not a full forensic perimeter. Revolut has not disclosed the exact date the fraudulent request was received, the number of separate requests successfully answered, or which legal entity fulfilled them. The name of the impersonated agency also remains information the company has not shared.
The case lands at a delicate moment for the fintech. The Crypto Times earlier reported that Revolut received conditional approval from the United States Office of the Comptroller of the Currency (OCC) for a national bank charter on 3 September 2026, and is targeting a 2027 launch pending Federal Deposit Insurance Corporation (FDIC) and Federal Reserve approvals.
Customer funds and private keys were not taken in the current incident. Identity documents paired with Bitcoin transaction histories were, and for a subset of wealthy, crypto-active customers, that combination is what UK regulators are now examining.
Also Read: Balancer Plans to Return Treasury Assets to BAL Holders with Winddown
