What is phishing in practice? In Revolut’s case, it was an impersonation scam last week in which hackers posed as government officials and accessed customer data. The breach exposed information on about 680 customers, including people linked to suspected cryptocurrency holdings.
That is a tiny slice of Revolut’s 80 million global customers, but the files included personal details that can turn a breach into a safety problem. Mark Karpelès, a Revolut customer and former chief executive of Mt. Gox, said his address was in the files and that he feared for his family’s safety.
Mark Karpelès and the leaked files
Karpelès told, “I have kids, we’re living together. My address is in those files, so of course I’m worried about this,” and said he feared he could be “kidnapped or dead” before Revolut gave him more substantial information about the breach. He also contacted law enforcement in Tokyo after the breach.
He said in a victim chat group on X, “We’re all in the same situation, which is: we don’t know exactly what happened, or how it happened, so we’re trying to get as much information as possible,” which captures the practical problem for affected users: knowing what was exposed, and how far the exposure spreads beyond a single address.
Revolut and the $3m demand
The breach was followed by a reported $3m ransom demand. One alleged hacker reportedly threatened to publish the customer data unless Revolut paid $3m, and another victim was told the hacker had personal details on hand and would delete them only if sent $50,000.
Revolut said it had not received any direct contact or demand from the individuals or group making these claims. That leaves affected customers with a narrow but important task: treat any message asking for money or personal data as suspect, and assume that leaked information may be reused for further impersonation attempts.
Revolut’s stock plans
The data breach lands while Revolut is still moving toward a stock market debut. Earlier this summer, it was valued at $115bn in a secondary share sale, and on Thursday Nik Storonsky told Les Echoes that there were plans for a dual listing in both London and New York.
The unanswered question is whether the company will say more about the scope of the leaked files or how the breach could affect those stock market plans. For now, the story is not just that data was stolen; it is that a scam built on impersonation exposed who might be worth targeting next.







