Revolut told Reuters on September 16 that it had received no direct contact or demand from those claiming responsibility for a customer data breach. The Reuters report, carried by Euronext, followed reports of a public ransom ultimatum.

Reuters cited the Financial Times as reporting a $3 million demand and a threat to sell customer records. That is a reported claim by the attackers, not confirmation that negotiations occurred or that Revolut paid them.

What the company has acknowledged

Revolut previously said sensitive customer information reached an unauthorized third party after fraudulent requests arrived from a legitimate government agency email domain.

A source familiar with the matter told Reuters that approximately 680 customers were affected and that core infrastructure, databases and customer accounts had not been hacked. The count is an attributed estimate.

The distinction matters: unauthorized disclosure through an information-request process is different from evidence that attackers directly accessed customer accounts. The absence of direct contact does not negate the disclosure.