Invest1 publisher3 min readPublished
Revolut puts 150 million francs behind 1.3 million Swiss customers it already serves
Colombia's approval is Revolut's sixth banking licence and the FINMA filing would be its seventh. The same week, the bank was still working through a fraudulent legal request it honoured from a real government domain.
The Investor · Invest desk

What happened
- A day later Revolut confirmed it had filed for a Swiss banking licence with FINMA, an application that is under review with no assurance of approval.
- An unauthorised party sent fraudulent information requests from a genuine government-agency domain that passed authentication checks, and Revolut released customer files in response.
- Revolut called the affected population limited, while later reporting put it near 680 to 700 people, with targets reportedly picked in part for significant crypto holdings.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost The Swiss spend works out at 30 million francs a year, and no more than 115 francs per existing customer, all of it committed before the licence that makes the products legal to sell.
- exposure Every additional licence adds a country's police, tax and court mailboxes to the set of senders Revolut's staff have to trust, and one compromised Italian channel ran for months.
- contradiction Revolut says no direct demand reached it while an extortion site and ransom-style threats circulate publicly, which leaves the cost of the episode unsettled for anyone pricing it.
Revolut already has more than 1.3 million customers in Switzerland, served through its Lithuanian bank and a local representative office [7]. It cannot yet sell them franc-denominated salary accounts or full Swiss deposit protection [8]. The company says it intends to invest more than 150 million Swiss francs there over five years and to build a standalone Swiss entity [10]. That is 30 million francs a year [1], or no more than about 115 francs per customer it already has [2]. A licence would add Swiss IBANs, payroll accounts, eBill, merchant acquiring and, later, possibly Pillar 3a pensions and Twint [9].
Colombia is the reverse case. The supervisor's approval completed the last regulatory step before Revolut can open as a locally regulated bank [1]. Officials and company sources have pointed to a 2027 start [3], and roughly 200,000 people are on a waitlist [4]. The commitment there is described only as tens of millions of dollars on top of capital already pledged [5]. Take 20 million as the low end of that phrase and the waitlist has cost 100 dollars a name [3].
The security episode running alongside was social engineering, not a break-in of Revolut's systems [11]. An unauthorised party sent information requests from a genuine government-agency email domain; the messages passed standard authentication checks, Revolut treated them as legitimate legal demands, and it released customer files [12]. Those files included passports, driving licences, verification photos, account statements, IBANs and transaction histories, with cryptocurrency activity in some cases [13]. Revolut has called the affected population limited, while later reporting put it near 680 to 700 people, with targets reportedly chosen in part for significant crypto holdings [14].
People claiming responsibility said they had used a compromised Italian official email channel for several months while posing as law enforcement [17]. Revolut blocked the address, notified the agency, law enforcement and regulators, and contacted the customers involved [16], and says its platforms and customer funds were not compromised [15].
The process that answers legal demands failed. It grows one jurisdiction at a time: six licences now [2], a seventh under review [4], each bringing its own police, tax and court mailboxes for a compliance team to authenticate. Revolut did not say whether FINMA has raised the incident [20].
I would expect the licences to keep landing anyway. Revolut says funds were untouched [15], five supervisors granted authorisations before Colombia's [2], and a regulator will see one broken control in 690 files released through a forged demand. The version where I am wrong is narrow and specific. FINMA treats those files as evidence about controls inside the entity it is being asked to license, and the review sits while Revolut documents how it verifies a legal request. The application is under review, and approval is not assured [6].
What to watch
- Whether FINMA's review of the Swiss application slows or asks for the incident file before ruling.
- Whether the 2027 Colombian opening date holds once local build-out spending is disclosed in figures.
- Whether the group claiming the Italian email channel makes a direct demand to Revolut or publishes the files.