Revolut Faces $780M Bitcoin Extortion After Falling Victim to Data Breach Scam

2 hours ago 14

Key Takeaways

  • Social engineering attack led Revolut to unknowingly share customer information with cybercriminals disguised as authorities
  • Approximately 680 users had confidential information compromised, including identity documents, financial records, and cryptocurrency transactions
  • Cybercriminals are extorting the company for 10,000 Bitcoin (approximately $780 million) with threats of ongoing data publication
  • British regulators at the Information Commissioner’s Office have initiated a formal probe
  • The security incident may impact Revolut’s forthcoming $200 billion public offering

Digital banking platform Revolut has acknowledged falling victim to an elaborate scam where cybercriminals successfully obtained confidential customer information by masquerading as governmental authorities. Approximately 680 users were impacted by the security incident.

🚨BREAKING: Revolut attackers demand 10,000 BTC ransom, threatening to leak stolen customer data.

The threat actors who allegedly tricked Revolut into handing over sensitive customer data by posing as a government are now publishing information belonging to high-profile clients.… https://t.co/kJi58fAHaa pic.twitter.com/5IIaCHHOYT

— Coin Bureau (@coinbureau) September 14, 2026

The perpetrators dispatched a deceptive inquiry utilizing an authentic government email account. Acting on what appeared to be a legitimate official request, Revolut disclosed sensitive customer information including passport credentials, banking account identifiers, residential locations, verification photographs, government-issued identification cards, and Bitcoin transaction records.

Following the data acquisition, the threat actors initiated extortion efforts, threatening public disclosure of the compromised information without payment. The ransom has been specified as 10,000 Bitcoin, valued at roughly $780 million based on current Bitcoin market rates hovering around $77,974.

Details of Compromised Information

The exfiltrated data encompasses transaction logs, financial statements, identity verification selfies, and scanned identification documents. Contact numbers and physical addresses were similarly exposed in the breach.

On-chain investigator ZachXBT indicated via Telegram that the operation seemed specifically designed to compromise wealthy account holders. Evidence circulating online revealed that the attackers had begun publishing information belonging to Felix Römer, who serves as CEO of cryptocurrency gaming platform Gamdom.

Mark Karpelès, previously the chief executive of defunct digital currency exchange Mt Gox, was also identified among the victims. He received notification from Revolut at 5:25 a.m. on September 12 indicating potential data exposure. Karpelès expressed his view that Revolut should never have disclosed the information, even if the request seemed authentic.

The threat actors have criticized Revolut for alleged carelessness and for distributing customer information to nations beyond its regulatory authority.

Company Statement and Regulatory Action

Revolut characterized the incident as a “sophisticated external impersonation scam.” The financial technology firm stated it immediately disabled the fraudulent email account upon discovering the deception.

The organization confirmed it alerted appropriate regulatory bodies and personally informed each impacted customer. Revolut self-reported the incident to the UK’s Information Commissioner’s Office, which announced Monday it had commenced a formal investigation.

The digital bank spent the weekend addressing the crisis. Officials characterized the total number of compromised accounts as “limited.”

The incident arrives at a particularly challenging moment for Revolut. The firm has been preparing for an initial public offering projected at approximately $200 billion, substantially exceeding its latest private market valuation of $75 billion.

A security breach of this magnitude, coupled with extortion demands and an active regulatory examination, complicates the IPO timeline.

The cybercriminals have allegedly stated they intend to publish customer information daily until their ransom demands are satisfied. Whether any payment has been made remains unconfirmed.

The post Revolut Faces $780M Bitcoin Extortion After Falling Victim to Data Breach Scam appeared first on Blockonomi.

Read Entire Article