Revolut said it has not received any direct ransom demand after a data breach exposed files linked to about 680 customers in Europe, disputing reports that attackers sought 6,000 XMR, or roughly $3 million, to keep the material from being sold.
The company said the incident stemmed from a social engineering campaign that lasted several months. According to Revolut, the attackers posed as government authorities and obtained customer verification files, identity documents, and transaction records, while customer funds and the firm’s internal systems were not compromised.
Company response to the reported extortion claim
The denial came after reports circulated that the hackers had demanded payment in monero in exchange for withholding the stolen data from the market. Revolut said it has not been contacted directly with such a demand.
That distinction leaves open the broader concern around the stolen files, but the company’s position is that no direct ransom approach was made to it. Revolut did not indicate in the source report that customer money or core infrastructure had been affected by the breach.
How the breach unfolded
Revolut said the attackers relied on impersonation rather than a direct technical compromise of internal systems. Over a period of months, they allegedly presented themselves as government authorities in order to persuade the company to hand over sensitive information.
The material obtained included verification files used for customer checks, identity documents, and transaction records. The case underlines how prolonged social engineering can bypass normal expectations of cybersecurity by targeting staff processes and trust relationships instead of payment systems or platform architecture.
Steps taken after discovery
Once the breach was identified, Revolut said it blocked the fraudulent email address involved in the scheme. The company also reported the incident to law enforcement, data protection authorities, and financial regulators.
Based on the company’s account, the immediate response focused on containment and formal notification. Revolut also stressed that the breach did not extend to customer funds and did not compromise its internal systems.
Why identity data has become a target
Jonathan Riss, an analyst at Certik, said strict know-your-customer requirements can turn platforms into attractive targets because they are required to store large volumes of sensitive personal data. In his view, regulators should revisit how much information firms truly need to collect and how long that data should be retained.
Riss also argued that authorities should ensure secure procedures when requesting information from platforms. He pointed to the particular risks of exposing detailed identity records in the digital asset sector and said companies should reduce unnecessary retention, limit who can access such data, and tighten verification for requests claiming to come from government or law enforcement bodies.
What is confirmed so far
At this stage, the confirmed facts in the source report are limited but significant: around 680 European clients were affected, sensitive customer records were taken, and Revolut says no direct ransom demand was made to the company.
The next confirmed step is the ongoing handling of the case by the authorities and regulators that Revolut said it has already notified. Any further assessment of the reported monero demand or the fate of the stolen data remains dependent on developments beyond the company’s current statement.
Source: news.bitcoin.com