Revolut, the British fintech giant, notified potentially affected users last week after attackers siphoned the personal data of roughly 680 high-profile customer accounts — many of them high-balance crypto holders — over a five-month window, according to SecurityWeek. The Guardian reported the company is now facing a ransom demand reported at around £2.2–3 million.
The attackers posed as government officials, using counterfeit official data requests to induce Revolut staff to hand over customer information, according to multiple outlets; Cybernews reported the fake requests were framed as Italian government orders. The Irish Times reported the public demand as 6,000 Monero (XMR) — roughly $3 million — with the message: "otherwise all the data will be sold, and the blood will be on your hands." The Observer put the number of compromised "crypto whale" accounts at nearly 700.
The stolen material reportedly includes identity documents and account data for customers whose balances make them targets offline as well as on. One victim quoted by The Guardian said he now fears for his physical safety. The ransomware-style demand — pay in privacy coin or the data is sold — is the attackers' claim, and the full scope of the leak remains unverified; what is confirmed is Revolut's own notification to affected users.
Why This Incident Is Different
No private keys were compromised and no funds are reported stolen from wallets. The exposure is informational — and that is precisely what makes it dangerous. A dataset that maps named individuals to large crypto balances converts an anonymous asset class into a kidnapping, extortion and burglary risk. It is the same threat model that made exchange data breaches a standing concern for high-net-worth holders, now executed through a regulated fintech's compliance channel rather than its servers.
The procedural failure point — staff responding to spoofed governmental urgency — is one of the oldest in the book, and the countermeasures are procedural too: verified channels for legal data requests, out-of-band confirmation, and rate-limiting what any single support process can disclose. For affected customers, the practical guidance is operational: assume address and identity exposure, tighten physical security, and treat any unsolicited contact that references holdings as hostile until proven otherwise.
TrustGrade tracks the security posture of platforms and firms in digital assets. Verified trust data: trustgrade.ai.