Mark RadarMARK RADAR
About
EN
Sign in

Former Revolut Employee Accused of Seeking Crypto Ransom Over KYC Data

1 reports · First detected 2026-02-24 · Last active 2026-02-24

Revolut is a fintech company offering cross-border payments, banking and cryptocurrency trading services, and is legally required to retain customer know-your-customer (KYC) data. A trader alleged that a former employee used workplace access to obtain the trader's personal information, then demanded cryptocurrency by threatening to leak the data and harm the trader's family. The case highlights the risks posed by insiders with access to sensitive information.

Revolut confirmed that it had reported the case to law enforcement and launched an internal investigation, stressing that its systems had not been breached by external hackers. As of July 20, 2026, reports had not identified the former employee, specified the type or amount of cryptocurrency demanded, or disclosed the exact dates of the threats and the report to authorities.

All Coverage

1 original reports

The Backstory

The history behind this event
After this
Revolut Rejects Claim of 75 Million-Customer Data Breachfirst seen 2026-08-03 · 1 reports · similarity 0.80 · same topic: Revolut

Revolut, a UK-based fintech company offering banking and payment services through its mobile app, has a large customer base that makes any alleged data exposure a significant cybersecurity concern. Listings of financial records on dark-web forums can raise the risk of fraud and identity theft, while also testing customer confidence and drawing scrutiny of a company’s data-protection controls.

As of Aug. 3, 2026, a hacker claimed to be selling 75 million purported Revolut customer records on the dark web for $500. Revolut said it compared and validated the material and found no evidence that its systems had suffered a data breach. The company concluded that the dataset was highly likely to have been fabricated rather than obtained from genuine customer records.

Revolut Hands Customer Data to Fraudster After Fake Government Requestfirst seen 2026-09-12 · 4 reports · similarity 0.82

Revolut disclosed sensitive customer records to an unauthorized third party after treating a fraudulent information demand as a legitimate government request. The incident is significant because the files linked customers’ real-world identities — including passports, verification selfies and home addresses — with IBANs, account statements and complete Bitcoin transaction histories, creating risks ranging from identity theft and targeted phishing to physical threats against cryptocurrency holders.

Revolut began notifying affected customers on Sept. 11, 2026, and the incident became public the following day after posts by on-chain investigator ZachXBT and former Mt. Gox CEO Mark Karpelès. The request came from an unauthorized account operating within a government agency’s genuine domain and carried valid authentication credentials. Revolut said it blocked the sender and alerted police and regulators, but has not identified the agency or disclosed how many customers were affected. Login credentials, facial biometric telemetry and customer funds were unaffected, leaving reported financial losses at zero.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)