Revolut Data Breach Escalates as Attackers Demand 10,000 BTC

Fraudulent government-domain requests exposed customer records before the incident developed into an extortion campaign
TL;DR
- Revolut confirmed an unauthorized customer-data disclosure after fraudulent requests came through a legitimate government domain.
- Attackers were later reported to be demanding 10,000 BTC while threatening progressively larger releases of customer information.
- Revolut said its internal systems were unaffected and customer funds remained safe.
Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
Revolut’s customer-data breach escalated into an alleged extortion campaign by September 14, 2026, with attackers reportedly demanding 10,000 BTC and threatening further disclosures after fraudulent government-domain requests caused the company to release sensitive customer information. Revolut confirmed the underlying data exposure but characterized it as an “external impersonation scam,” saying its internal systems were not compromised and customer funds remained safe. The ransom demand, claimed high-profile victims and newly published material had not been confirmed by Revolut.
Fraudulent government-domain request passed Revolut checks
The incident began around September 12, when Revolut disclosed that customer information had been released to an unauthorized party after fraudulent requests arrived from an email address hosted on a legitimate government domain. The apparent impersonation allowed the requests to clear Revolut’s checks before the company recognized them as fraudulent. Revolut said a limited number of customers were affected. The company serves about 80 million customers across 30 countries, but that figure represents its total customer base rather than the number of people exposed.
Revolut told affected customers that potentially disclosed information included dates of birth, postal addresses, email addresses, phone numbers and copies of identity documents, including passports and driving licenses. Verification selfies, account statements and transaction histories may also have been released. ZachXBT separately said additional exposed fields included IBANs, withdrawal records, occupations and transaction histories covering Bitcoin. Those additional categories were attributed to ZachXBT rather than included in Revolut’s own listed disclosure.
ZachXBT assessed the incident as limited in scale and apparently focused on high-net-worth users. Revolut did not state that wealthy customers or cryptocurrency holders were specifically targeted. The combination of identity documents, addresses, contact information and Bitcoin transaction records raised concerns because it could connect information about a person’s real-world identity with financial activity that would otherwise sit separately from those identity records.

Revolut blocked the fraudulent sender’s address across its internal systems after identifying the scheme and contacted the government agency whose domain had been abused. The company also notified law enforcement, data-protection authorities and financial regulators and introduced precautionary protections for affected customers. Revolut contacted affected customers directly as part of its response.
Attackers threaten expanding customer-data releases
By September 14, the incident had developed into an alleged extortion campaign. International Cyber Digest said attackers had begun releasing information purportedly linked to high-profile Revolut customers, including tennis player Shevchenko and Gamdom CEO Felix Romer. Revolut had not authenticated the newly leaked material or confirmed those individuals as victims. The appearance of a name in attacker-released material alone was not treated as proof that the person had been affected because threat actors may combine genuine, outdated, fabricated or separately obtained information.

Attackers were reportedly publishing customer passports and selfies while threatening progressively larger releases if Revolut refused to pay. A message attributed to the attacker said, “We’re gonna start releasing more and more data everyday until Revolut pays for leaking their customers.” The extortion effort therefore relied on continuing disclosure of customer information as leverage rather than only threatening future publication.
The 10,000 BTC ransom demand surfaced through a social-media claim on September 14. Revolut had not confirmed the demand, the attacker’s identity or the authenticity of the newly released records. The underlying unauthorized disclosure, however, had already been acknowledged by the company, creating a clear distinction between the confirmed impersonation incident and subsequent attacker-linked claims about the scale, identities involved and ransom.
Mert warned on September 12 that exposure linking personal identities with crypto-related financial records could contribute to “home invasions and losing millions.” Mert argued that conventional identity-verification processes should be replaced where possible with privacy-preserving approaches, specifically calling for “ZK-based KYC.” The supplied material also described zero-knowledge proofs as a potential way for institutions to verify required information without collecting or sharing more personal data than necessary.
No documented downstream misuse beyond the claimed publication and extortion activity was established. The material did not establish that customer accounts had been drained or that the exposed information had already resulted in physical attacks. It did, however, identify targeted social engineering as a near-term concern because detailed KYC records and transaction information could provide attackers with enough personal context to craft more convincing impersonation or phishing attempts.
This article has been refined and enhanced by ChatGPT.