British fintech company Revolut confirmed that sensitive customer information for nearly 700 individuals was disclosed to an unauthorized third party. This occurred after the company received fraudulent requests for data from an email address belonging to a legitimate government agency domain. The compromised data included customers' birth dates, postal and email addresses, phone numbers, copies of identity documents (such as passports and driver's licenses), verification selfies, bank statements, International Bank Account Numbers (IBANs), withdrawal records, and transaction histories, including Bitcoin activity.

Revolut stated that it identified a "sophisticated external impersonation scam" where the attackers exploited a legitimate government agency domain email to submit these fraudulent requests. While Revolut did not publicly identify the specific government domain, alleged extortion images circulated on Telegram by a group claiming responsibility suggest the email originated from an Italian domain, possibly ending in @interno.it. The company confirmed that its systems and customer funds were unaffected and that it immediately blocked the fraudulent address, alerting the relevant government agencies, law enforcement, data protection authorities, and financial regulators. Customers affected were notified directly.

The perpetrators reportedly targeted high-net-worth individuals, many involved in crypto asset businesses. Notable figures impacted include Marc Zeller, a cryptocurrency entrepreneur, and Mark Karpelès, the former CEO of the Mt. Gox bitcoin exchange. Reports suggest that some affected individuals received blackmail threats based on the stolen data months before Revolut informed them of the breach. The hacker group, calling itself Revolut Smilik, is reportedly seeking payment from Revolut and threatening to release more data if their demands are not met. Revolut has not commented on the existence of any extortion attempt. This incident is reminiscent of similar breaches in 2021 and 2022 where groups like Lapsus$ used compromised law enforcement accounts and forged emergency data requests to obtain user information from tech companies.

The Information Commissioner’s Office (ICO) in the UK has received a report and is assessing the information, while the Financial Conduct Authority (FCA) is engaging with Revolut to understand the impact. Revolut, which boasts over 80 million customers globally and operates across 30 countries, is reportedly considering a public listing that could value it at up to $200 billion. The company emphasizes that only a "very limited" number of customers were affected, though the exact number mentioned in reports is around 680-700 individuals.