Fintech company Revolut has mistakenly handed over sensitive customer data after falling for fake government requests. The self-proclaimed culprits behind the breach have demanded a ransom of 10,000 Bitcoin. The exposed information reportedly includes passports, selfies, and transaction histories, putting customer privacy at significant risk.
This incident occurred when Revolut received what appeared to be legitimate government requests for customer data. However, these requests were fraudulent, leading the company to disclose highly sensitive information without proper verification. The breach highlights vulnerabilities in Revolut’s data security and response protocols to external demands.
The development matters because it exposes the potential risks fintech companies face when handling sensitive customer information. As digital financial services grow, the ability to verify and authenticate data requests is critical to protecting user privacy and maintaining trust. This breach could have far-reaching implications for Revolut’s reputation and customer confidence.
Revolut’s response to the fake requests was intended to demonstrate compliance with regulatory demands, but it instead revealed weaknesses in its verification processes. The incident underscores the need for stronger safeguards and more rigorous checks before releasing customer data, especially in the face of sophisticated social engineering attacks.
What remains uncertain is the full extent of the data compromised and how Revolut will address the fallout. It is also unclear how the company plans to prevent similar incidents in the future. Observers will be watching closely for updates on Revolut’s security measures and any regulatory actions that may follow.



