The Revolut data breach has rapidly escalated into an active extortion campaign, with attackers publishing sensitive customer passports and selfies online. Fintech users and cybersecurity professionals monitoring the fallout must now navigate a scenario where immutable identity documents and crypto transaction histories are being weaponized for ransom.
The attackers have taken to Telegram, threatening to release more customer data daily until the financial institution pays a ransom. While Revolut has not confirmed the ransom amount or the total number of affected users, high-profile clients, including former Mt. Gox chief executive Mark Karpelès, tennis player Shevchenko, and Gamdom CEO Römer, have been identified among the victims.
The exposed data carries severe extortion value because it cannot be easily reset like a password. Compromised information includes full names, dates of birth, occupations, postal and email addresses, phone numbers, passport and driving-licence copies, and verification selfies. Furthermore, the leak exposes account statements, IBANs, and full transaction histories, including specific records of Bitcoin activity.
Unlike a traditional database hack, this breach was executed through a fraudulent emergency data request (EDR). The attackers emailed a request for customer records using an address hosted on a legitimate government agency’s domain. Because the correspondence passed internal checks by originating from real agency infrastructure, the unauthorized sender successfully bypassed standard security protocols.
Revolut has since blocked the address and notified law enforcement, data-protection authorities, and financial regulators. However, this fake EDR vector is a systemic industry flaw with a documented history. In 2021, teenage hackers affiliated with the Recursion Team and Lapsus$ groups used compromised police accounts to extract user data from Apple, Meta, and Discord, prompting a specific FBI warning in November 2024 about a spike in these attacks.
How to Mitigate Fake EDR Attacks
Security teams and regulated brokers must implement stricter verification protocols to counter the asymmetry of fraudulent requests. Relying solely on domain authentication is no longer sufficient when dealing with the roughly 18,000 law-enforcement jurisdictions in the United States alone.
- Implement out-of-band callback verification by contacting the requesting agency through a publicly published phone number.
- Log and cross-check every incoming law-enforcement request to identify suspicious patterns or first-time contacts lacking history.
- Utilize pooled intelligence across financial firms to detect if the same fraudulent requester is approaching multiple institutions simultaneously.
The Verification Gap Threatening Fintech Expansion
The escalation of this breach exposes a critical vulnerability in how financial institutions handle the friction between legal compliance and data security. Emergency data requests are intentionally designed for speed to address imminent threats, often bypassing the need for a court order. Every optimization for speed in this channel inherently creates a verification gap that state-backed actors and extortionists are now actively exploiting.
This incident lands at a particularly sensitive time for Revolut as it expands into United States banking and stablecoins after securing preliminary approval for a national bank. Building a business on holding immutable identity and transaction data requires a zero-trust approach to external communications. If a single compromised police email account can bypass the defenses of a major fintech platform, the entire industry must shift from isolated verification to mandatory, cross-industry cryptographic proof of identity for all law enforcement requests.