Search
Choose a style
Dark
Light
Time to read: 3 min

Revolut data leak escalates with ransom threat 

Cluj-Napoca, Romania - 30 January, 2025: Revolut app on the smartphone screen. Revolut is a global neobank and financial technology company
Editorial credit: Melinda Nagy / Shutterstock.com

Around 680 Revolut customers were reportedly affected, with the information including identity documents, account details and transaction histories. 

A group claiming to be behind Revolut’s recent data leak has published customer information and threatened to release more unless the fintech pays a ransom.

Going by the name IAmNotAVillain, the group has launched a website and taken responsibility for the operation that saw Revolut release sensitive customer information in response to fraudulent requests sent through a legitimate government agency email domain.

The challenger bank confirmed the incident on 12 September but didn’t share many details, such as which markets were affected, how many customers were involved and which government agency had been impersonated.

However, the launch of the website on 14 September and discussions between the group and several publications have provided more information about the alleged scale of the scam.

IAmNotAVillain has published material including passports and Know Your Customer (KYC) selfies belonging to named individuals and is threatening to release more customer information unless Revolut pays.

The exposed information includes driving licences, addresses, IBANs, account statements, withdrawal records and full transaction histories, including bitcoin activity.

Revolut has said that its systems weren’t breached and customer funds are safe.

Screenshot of IAmNotAVillain website - Credit: Dark Web Informer on X
Screenshot of IAmNotAVillain website – Credit: Dark Web Informer on X

Nearly 700 customers affected

The Financial Times reported that Revolut notified 680 customers following the incident, representing a small percentage of its more than 80 million global customers. However, the type of information exposed could have serious consequences for the individuals involved.

Identity documents, KYC photographs, addresses and account information can be used to create profiles of victims. Transaction records may also hand criminals information that can make phishing, impersonation or account takeover attempts more convincing.

Several high-profile individuals have been linked to the breach. Felix Römer, CEO of Gamdom, has publicly said his information was compromised, while tennis player Alexander Shevchenko and footballer Georges Mikautadze have also been reported as having data exposed.

Römer said on X that attempts to exploit the stolen information commenced well before Revolut publicly confirmed the breach.

“Already 2 months ago me and others started to get blackmailed with the compromised data,” he wrote.

He also criticised the timing of Revolut’s communication, claiming the incident was only “properly communicated” once the disclosure of sensitive customer information became public.

Attackers make wider claims

International Cyber Digest said on X that it had been in contact with IAmNotAVillain, which claims it compromised Italian law enforcement systems and used them to request customer information from Revolut.

The group claims the operation ran for around six months and that it holds 147GB of data taken from the Italian side, including internal documents, calendars and officer communications. However, these claims haven’t been independently verified.

International Cyber Digest has also reported that the attackers say most of the Revolut customer data obtained relates to people in Switzerland and France.

However, the group claims information was also released on customers in Cyprus, Portugal, Germany, Spain, Bulgaria, Czechia, Romania, Poland, Malta, Norway, Sweden, Italy, Greece, the Netherlands, Latvia, Austria, Belgium, Estonia, Croatia, Ireland, Slovakia, Finland, Lithuania, Hungary, Denmark, Turkey, Monaco, Luxembourg, the Bahamas, Slovenia and the UK.

Subscribe to our newsletter