Hard numbers have emerged in the fintech's data breach, including a threat group's ransom demand of 10,000 bitcoin and confirmation that stolen data includes customers' bitcoin transaction histories.
The scope of Revolut's data breach has come into sharper focus, with confirmation that approximately 680 customers across countries including Ireland, Spain, and Romania have been affected. A threat group identifying itself as "Revolut Smilik" has demanded a ransom of 10,000 bitcoin, worth roughly $780 million at current prices, and has threatened continued data releases if the demand is not met.
The exposed data spans several categories: identity information such as names, dates of birth, and occupations; contact details; know-your-customer documents including passport and license copies and onboarding selfie images, though not biometric facial-recognition match data specifically; and financial records including account statements, bank routing details, withdrawal records, and, notably, customers' bitcoin transaction histories. That last category is what elevates this beyond a standard fintech data breach for crypto holders specifically, since a leaked bitcoin transaction history can potentially be used to link a person's real-world identity to their broader on-chain activity, a form of exposure that goes beyond the account numbers and personal details typically compromised in a financial breach.
Regulators in the United Kingdom have confirmed they are engaged. The Information Commissioner's Office said it has received a report on the incident and is assessing the information provided, while the Financial Conduct Authority said it is aware of the reported incident and is engaging with the firm. Revolut has said its own systems, databases, and customer funds were not compromised.
Given the relatively small number of confirmed affected customers against Revolut's global base of more than 80 million users, the breach's importance lies less in its overall scale and more in the specificity and sensitivity of what was taken, along with the size of the ransom demand relative to typical extortion attempts of this kind. How Revolut and the affected regulators respond in the coming weeks, and whether the threat group follows through on its threat of further releases, will determine whether this becomes a contained incident or a longer-running story for the company and its customers.
