The attack specifically targeted high-net-worth clients holding significant crypto assets. One fraudster, "IAmNotAVillain," claimed to have 147GB of data and demanded $3 million in ransom, while another group, "Revolut Smilik," demanded 10,000 Bitcoin (approximately $780 million).
In a breakthrough, ECFIU investigators traced the breach to an Eastern European data center, breached the building, and seized multiple servers containing critical evidence. No arrests have been made, and the investigation continues.
Revolut stated its core systems and customer funds were not compromised and has notified affected customers and the UK's ICO. Parallel investigations are underway across multiple European countries.
"This represents one of the largest data breaches in European financial history," an ECFIU spokesperson stated. "We have located the data center and seized crucial servers, but our work is far from over."
The ECFIU urges Revolut users to treat any calls, texts, or emails claiming to be from their bank or a government agency with extreme suspicion. A dedicated support portal has been established for affected customers.
Amsterdam, Netherlands. September 16, 2026.