The Crypto Times reports Revolut has confirmed that approximately 680 customers were affected in the customer-data disclosure incident:
The 680 figure was first reported by the Financial Times, which described the group as “nearly 700.” A source close to the bank confirmed the number to City AM, which said Revolut had contacted all affected customers directly. The 680 total represents roughly 0.00085% of Revolut’s more than 80 million global customers. National breakdowns published on 15 September have begun to fill in the geographic map: 12 customers in Ireland, against a local base of about 3.4 million, according to RTÉ; 25 in Spain, according to El Español; and 27 in Romania, according to Profit.ro.
Threat actors calling themselves Revolut Smilik are demanding a ransom of 10,000 Bitcoin (BTC) while threatening to release stolen files daily. Their initial Telegram account was quickly suspended.
The Revolut incident has also generated discussions about cyber insurers because what happened in this case is not the typical business email compromise or scam. As reported in Insurance Business Magazine:
Most social engineering endorsements are triggered by a transfer of funds, not a transfer of data. A scam where nothing is paid out but a large volume of identity and biometric data leaves the building can fall between a crime policy, built for financial loss, and a data breach policy, often built around unauthorised access rather than a fraudulent-but-convincing request. Brokers reviewing fintech and financial services clients’ wording may want to check whether “fraudulent instruction” definitions extend to information requests, not just payment instructions.
