Revolut Says No Group Has Made Direct Contact After Data Breach
Revolut Ltd. said no individual or group has made direct contact or demand almost a week after the fintech reported a scam involving an unauthorized third party that exposed sensitive information of some customers.
A spokesperson for the London-based firm commented Thursday in response to a Financial Times report detailing a public ultimatum on the website of hackers claiming they were behind the data breach. It demanded a ransom of $3 million within 24 hours, failing which they would sell the confidential information.
The fast-growing company, which was valued at $115 billion in July, said on Sept. 12 that a “limited number” of customers’ data was affected by the breach, understood to be some 680 accounts. As soon as it detected the scam, Revolut said it blocked the address — a legitimate government email domain — and alerted relevant authorities, including law enforcement.
Revolut also said that its systems and customer funds were unaffected by what it called “a sophisticated external impersonation scam” and it had offered support to those impacted by the breach.
The fintech has more than 80 million customers globally, with a goal of reaching 100 million. It received conditional approval in early September to operate as a national bank in the US, which it has identified as a key market.
Photograph: Company branding at the offices of Revolut Ltd. near La Bourse in Paris; photo credit: Nathan Laine/Bloomberg