Revolut said last week that it had been hit by an impersonation scam that exposed the personal data of about 680 customers, and one of the people caught up in it says his address was among the files taken. Mark Karpelès said he feared for his family’s safety after learning that information tied to him had been pulled from the breach.
The scale was small beside Revolut’s 80 million global customers, but the nature of the files made the case feel far larger to those inside it. The breach is believed to have focused on customers with suspected cryptocurrency holdings, a detail that helps explain why personal addresses were so sensitive and why some victims worried about more than account security.
That is the reason people are searching for what is phishing now: the breach was not a technical smash-and-grab, but a social trick. Hackers posing as government officials used an impersonation scam to persuade Revolut staff to hand over customer details, and the company said it had not received any direct contact or demand from the individuals or group making the claims. Yet one alleged hacker reportedly threatened to publish the data unless a $3m ransom was paid, while another told a victim the information would be deleted only if $50,000 was sent.
The gap between those claims matters because it leaves victims with no clear answer about who held the files, how far they had spread, or whether the data was ever secure after it left Revolut’s hands. Karpelès, who became a Revolut customer in 2023, said he contacted law enforcement in Tokyo after saying he feared he could be kidnapped or dead before the company gave him more substantial information, and he later said he was relieved that Japanese officials were taking the threat seriously.
Revolut is Europe’s largest financial technology company and has been preparing for a potential stock market debut after a $115bn secondary share sale earlier this summer. Nik Storonsky also said there were plans for a dual listing in London and New York, which puts added pressure on the company to show it can contain a breach that touched a relatively small slice of customers but exposed the kind of information that can make a personal risk feel immediate. What happens next is simple and uncomfortable: whether the files are published, sold or dropped will tell victims far more than any statement the company can issue now.

