The 24-hour deadline for a $3 million ransom demand against Revolut has lapsed, with no confirmed payment or subsequent sale of customer data. As of Friday, September 18, no independent verification of the extortion attempt's success has emerged, and Revolut maintains it never received a direct ransom demand.
The incident, which the company describes as a targeted phishing attack, involved an unauthorized party using a legitimate government-agency email domain to trick Revolut into disclosing sensitive customer information. This method differs significantly from a traditional ransomware attack, as the attackers did not breach Revolut's core systems but instead manipulated employees through a fraudulent but authentic-looking request.
Scope of the Breach
According to a source cited by Reuters, approximately 680 customers were affected, a fraction of Revolut's more than 80 million retail customers. The company confirmed that its core infrastructure, databases, and customer accounts were not compromised. Revolut has blocked the email source, notified authorities, and is contacting affected customers.
Customer notices reviewed by TechCrunch indicate that the exposed data may include contact details, identity documents, verification selfies, account statements, and transaction histories. Revolut emphasized that customer funds remain unaffected.
Phishing, Not a Core System Hack
This incident is a textbook example of phishing, albeit an unusually sophisticated one. The attackers impersonated an authority entitled to request records, using a certified email account associated with the Reggio Calabria prefecture in Italy, as reported by ANSA. The Italian postal police have opened an investigation.
The key control failure appears to be that Revolut treated a message from an authentic domain as sufficient proof of the sender's identity and the legitimacy of the request. A robust process would require secondary verification through independently maintained contact details, approval proportional to the sensitivity of the data, and a clear audit trail. The current reporting does not clarify which of these checks were in place or failed.
Valuation and Investor Confidence
Revolut is a privately held company, so there is no direct public stock reaction. Its most recent share sale in November 2025 valued the company at $75 billion, with investors including Coatue, Greenoaks, Dragoneer, and Fidelity Management & Research. The company's 2025 annual report shows $6.0 billion in revenue, $2.3 billion in pre-tax profit, and $67.5 billion in customer balances.
At roughly 680 affected accounts, the breach represents less than 0.001% of Revolut's customer base. This is the strongest argument against treating the incident as an earnings event. Even if remediation costs several hundred customers, it would be immaterial compared to $6 billion in annual revenue. However, the risk is nonlinear: passports, facial-verification images, and transaction histories cannot be reset like passwords. Any follow-on fraud could erode customer trust, and regulatory findings could impact Revolut's controls as it seeks licenses and converts users into primary-bank customers.
Regulatory and Market Context
Revolut recently received a Colombian banking license, adding to its approvals in six markets. This expansion underscores the importance of regulatory execution in its valuation story. The breach could invite scrutiny from data-protection authorities, potentially leading to fines or mandates for stronger verification processes.
Investors and analysts will be watching for updates on the number of affected customers, regulator findings on authentication failures, reports of identity theft or fraud, and any new verification procedures Revolut implements. Until then, the incident appears too small to alter near-term profit trajectory but significant enough to test the control quality embedded in a $75 billion valuation.



