Revolut Attackers Demand 10,000 BTC Ransom After Customer

Data Breach

Attackers who allegedly obtained sensitive Revolut customer information are now demanding 10,000 Bitcoin — worth roughly $780 million — in exchange for not releasing the data publicly. The ransom demand follows a recently confirmed incident in which an unauthorized party tricked Revolut into disclosing customer information through a fraudulent request that appeared to come from a legitimate government agency.

What Happened?

Revolut confirmed that an unauthorized third party used an email account within a legitimate government agency's domain to submit fraudulent requests for customer information.

Because the request appeared authentic, Revolut disclosed data before identifying the deception. The company said it subsequently blocked the email address, contacted authorities and notified affected customers.

Revolut has described the incident as a “sophisticated external impersonation scam” and said its systems and customer funds were not compromised.

Attackers Demand 10,000 Bitcoin

According to reports cited by Finbold, the attackers began threatening to publish customer and internal company information unless Revolut paid a ransom.

The reported demand is 10,000 BTC, valued at approximately $780 million when Bitcoin was trading near $77,974.

The attackers have reportedly already posted some information online, including data allegedly belonging to high-profile individuals.

However, the ransom demand and the attackers' claims have not been independently verified by Revolut.

What Customer Data Was Exposed?

Information potentially disclosed included:

  • Names and dates of birth
  • Home and email addresses
  • Phone numbers
  • Account statements
  • IBANs
  • Withdrawal records
  • Full transaction histories, including Bitcoin transactions
  • Copies of passports and driver's licenses
  • Verification selfies

Revolut said only a limited number of customers were affected and that it has contacted those individuals directly. The company has not disclosed the exact number of affected customers.

Customer Funds Were Not Stolen

The incident appears to be primarily a data exposure, rather than a direct theft of customer funds.

Revolut has said that its systems and customer funds remain unaffected. The company also blocked the offending email address after discovering the fraud.

However, exposed identity and transaction information could create secondary risks such as phishing, impersonation and targeted attacks against cryptocurrency holders.

Why Bitcoin Transaction Data Matters

The reported exposure of Bitcoin transaction histories makes the incident particularly significant for crypto users.

A leaked transaction history can potentially reveal information about a user's cryptocurrency activity and holdings. When combined with names, addresses or identity documents, that information could make high-value crypto users more attractive targets for future scams or social-engineering attacks.

Blockchain investigator ZachXBT has reportedly suggested that the incident may have disproportionately targeted high-net-worth individuals.

How Did the Attackers Bypass Verification?

The unusual element of the incident was the use of a real government domain.

According to Revolut's account, the fraudulent request came from an unauthorized mailbox within an official government agency's domain and carried legitimate domain authentication credentials. That made the request appear genuine to Revolut's verification process.

The incident therefore highlights a broader cybersecurity problem: a legitimate domain does not necessarily mean that every account operating under that domain is legitimate.

Could the Attack Affect Revolut's IPO Plans?

The incident comes at an important time for Revolut as the company continues expanding its banking and cryptocurrency operations.

The fintech has reportedly explored an IPO at a valuation of around $200 billion, significantly above its latest private valuation of roughly $75 billion.

A customer-data incident does not automatically threaten those plans, but cybersecurity and data-protection controls could receive greater scrutiny as Revolut expands.

What Revolut Users Should Watch

Affected and potentially affected customers should be particularly cautious about:

  1. Unexpected emails or phone calls claiming to be from Revolut.
  2. Requests for passwords, verification codes or wallet information.
  3. Messages referencing leaked account or transaction details.
  4. Phishing attempts using personal information from the breach.
  5. Unusual account activity or suspicious login notifications.

Users should contact Revolut through its official in-app support channels rather than links received through unexpected messages.

FAQ

Did hackers steal 10,000 Bitcoin from Revolut?

No. 10,000 BTC is reportedly the ransom demanded by the attackers, not Bitcoin stolen from Revolut or its customers.

Was Revolut's crypto system hacked?

Revolut has said its systems and customer funds were not compromised. The incident involved a fraudulent information request that resulted in customer data being disclosed.

What information was exposed?

Potentially exposed information includes identity documents, addresses, phone numbers, account statements and cryptocurrency transaction histories.

Has Revolut confirmed the $780 million ransom?

The 10,000 BTC demand has been reported by Finbold and other sources, but Revolut has not publicly confirmed the ransom amount. The investigation remains ongoing.

Final Take

The Revolut incident demonstrates how attackers can exploit trusted communication channels and social engineering without directly breaking into a company's core systems.

The reported 10,000 BTC ransom dramatically raises the stakes, but it remains an allegation until independently confirmed by Revolut or authorities.

For crypto users, the bigger concern may be the leaked combination of identity documents and Bitcoin transaction histories. Such information can create risks long after the original breach, particularly through targeted phishing and social-engineering attacks.