Felix Römer is still in shock from the email he got from his bank last weekend.
"Urgent security update about your Revolut account," the message read. It went on to say that some of Römer's most sensitive financial and personal information-such as his home address, a photo of his passport and transaction history-had fallen into the hands of a scammer.
Most confoundingly, the bank hadn't been hacked. London-based Revolut, among the most popular of Europe's breed of digital "neo-banks," had voluntarily handed his data to someone impersonating a government agency. By sending fake law-enforcement requests, the impersonator extracted data on hundreds of customers from the online bank, including well-off businessmen from the crypto world.
Now Römer, a German crypto entrepreneur who lives in Malta, has gotten caught up in a data breach that has embarrassed fast-growing Revolut and raised questions about its competence.
The news comes at an awkward time for Revolut, a fintech company that was recently valued at $115 billion, making it Europe's most valuable startup. Earlier this month, Revolut got a tentative greenlight to offer banking services to Americans, part of its ambition to crack the U.S. market.
The breach has prompted furious reactions from customers. About 680 customers were affected, a person close to Revolut said. While that is a small slice of the company's more than 80 million customers, the breach has drawn scrutiny for its apparent targeting of high-net-worth individuals active in digital currencies.
Customers have voiced alarm that the leaked data could expose them to "wrench attacks," in which criminals use the threat of violence to force bitcoin investors to hand over the digital keys to their assets.
"I am honestly surprised how a company of this size is storing my data and more so just giving it out that easily," Römer said.
Adding to Revolut's headaches, the company is facing extortion threats from a shadowy hacker who claims to be behind the breach. The purported hacker has released snippets of the stolen client data-including Römer's-and threatened to release more unless Revolut pays up, without publicly specifying an amount.
The company said it had alerted law enforcement, but declined to discuss the extortion threat. The U.K. Information Commissioner's Office, which oversees data protection, said it was looking into the matter.
Revolut called the incident "a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information."
The company hasn't been contacted by the perpetrators, the person close to Revolut said.
Mark Karpelès, the former chief executive of failed bitcoin exchange Mt. Gox, said he was one of the victims of the breach.
"They should have talked to a real human to confirm as bare minimum," Karpelès posted on X. In another tweet, he warned he "might be kidnapped or dead" by the time he received answers from Revolut about the breach.
In an email, Karpelès told The Wall Street Journal he had learned about the breach from Revolut's email early Saturday, and had taken "appropriate measures" to protect himself and his family.
Karpelès, a French businessman based in Tokyo, is a controversial figure in crypto. After the 2014 collapse of Mt. Gox, he was acquitted of embezzlement by a Japanese court but found guilty of falsifying data.
Since the security breach, a hacker calling themselves "I Am Not A Villain" has released materials that Revolut handed over by mistake. Among them were a passport photo and other information on Römer, the German entrepreneur. Römer told the Journal that the materials were authentic.
"We're gonna start releasing more and more data everyday until revolut pays for leaking their customers," I Am Not A Villain wrote in a post on a channel on Telegram, the social-media platform. The post was archived by cybersecurity researchers before the channel was deleted.
I Am Not A Villain has also posted screenshots of emails that suggest the scammer hijacked an Italian government email account, which communicated with an email address used by Revolut's Italian arm. Italian police didn't respond to a request for comment.
Scammers have long impersonated government agencies to send fake law-enforcement requests, and such tricks aren't especially difficult to pull off, said Conor Freeman, an Irish cybersecurity researcher who has been tracking the Revolut hack.
"It's not exactly rocket science," Freeman said.
Römer said he was considering stepping up security measures at his house. His business history makes him a potential target for a wrench attack: His ventures include a crypto-based online casino and a marketplace for virtual assets used in the hit videogame "Counter-Strike 2."
"Holding crypto and having your address exposed is basically inviting someone to rob you," said Römer. "It's easier than robbing a bank."