European business, markets and politics
A sophisticated impersonation scam has compromised the personal details of nearly 700 Revolut users, sparking a ransom threat and regulator involvement.

Revolut confirmed that a criminal group accessed the personal information of roughly 700 of its users. The attackers, who call themselves Revolut Smilik, have demanded payment and warned they will keep releasing data daily unless their demands are met.
The fraudsters used a convincing email that appeared to come from a legitimate government agency. By impersonating the agency, they submitted false requests for customer details, obtaining identity documents, postal and email addresses, phone numbers and facial‑verification images. The fintech firm says its core infrastructure, databases and account balances remain untouched.
“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators,” a spokesperson said.
Revolut has already notified the 680 affected individuals, describing the incident as a “sophisticated external impersonation scam”.
The Financial Conduct Authority confirmed it is in contact with Revolut to assess the impact and any potential harm to consumers. The Information Commissioner’s Office also received a report and is evaluating the breach under data‑protection rules.
London‑based fintechs have faced heightened scrutiny after high‑profile cyber incidents, such as the Jaguar Land Rover hack last year that cost the UK an estimated £1.9 billion.
Authorities may launch formal investigations, potentially leading to fines or mandatory security upgrades. For customers, the exposure of identity documents raises the risk of fraud and phishing attacks, prompting many to monitor credit reports and change passwords.
Revolut has not yet engaged directly with the hackers, and the group’s threats remain unverified. The company’s next steps will likely focus on reinforcing verification channels and reassuring users that their funds and core services are safe.