Revolut Data Breach Escalates With 10,000 BTC Ransom Demand

We may earn commissions from affiliate links or include sponsored content, clearly labeled as such. These partnerships do not influence our editorial independence or the accuracy of our reporting. By continuing to use the site you agree to our terms and conditions and privacy policy.

Article Details

The Revolut data breach escalates as attackers demand a 10,000 BTC ransom, threatening to leak sensitive customer records and passport copies.

The threat comes just days after Revolut confirmed it handed over sensitive data following a fraudulent request sent from an email account hosted on a legitimate government domain.

Ransom Demand Turns Revolut Data Breach Into a New Crisis

Yahoo Finance shared details regarding claims of a 10,000 BTC ransom, with the attackers threatening to progressively leak more customer files and information if Revolut fails to comply. With Bitcoin trading around $77,000, such a sum would value the ransom at approximately $770 million.

At this stage, neither the ransom amount nor the identity of the group has been verified. The reports are based on messages attributed to the alleged perpetrators, meaning the claim should currently be treated as unconfirmed.

However, this escalation alters the nature of the situation. What initially appeared to be a limited unauthorized disclosure now carries the risk of public extortion, fraud, or targeted attacks following the Revolut data breach.

Revolut Deceived by Legitimate Government Domain

The breach itself is unusual because the attackers did not directly infiltrate Revolut’s internal systems.

The company revealed that an unauthorized individual used an email account created within the infrastructure of a genuine state institution domain. The request for customer information sent from this address appeared authentic, leading Revolut to comply. Only during a subsequent follow-up check with the institution did the fintech company discover that the request was fraudulent.

Revolut described the incident as a sophisticated external impersonation scheme and stated that it blocked the corresponding email address immediately after discovering the deception.

The company has notified law enforcement, regulatory bodies, and data protection authorities.

Passports and Bitcoin History Increase Risk

The potentially exposed information is highly sensitive because it links the real-world identities of customers with their financial activities.

According to reports, the compromised data could include:

  • Names, dates of birth, addresses, emails, and phone numbers.
  • Copies of passports or driver’s licenses along with facial identification photos.
  • IBAN numbers, bank statements, and withdrawal records.
  • Full transaction history, including BTC operations.

The company has not disclosed the total number of affected clients, stating only that a limited number of users were impacted.

Attackers Target Revolut’s Data Security Practices

The alleged perpetrators are not just using the leak for financial leverage. They also accuse Revolut of negligence in protecting personal information, claiming the company provided sensitive data to states outside their own jurisdiction.

These allegations remain independently unverified, and Revolut has not acknowledged any such compliance failures.

Nevertheless, the case raises questions about the procedures financial firms use to verify requests from government institutions. The presence of a legitimate state email domain proved convincing enough to trigger the release of detailed KYC and financial data without the attackers needing to breach the fintech company’s infrastructure directly.

Pressure Mounts at a Sensitive Time for Revolut

The incident comes at a critical moment as Revolut accelerates its expansion into traditional banking and crypto services. The company currently serves around 80 million customers globally and is scaling its business toward larger corporate clients.

Revolut emphasized that customer funds, passwords, PIN codes, and its internal systems were not compromised during the initial incident.

However, the public release of actual customer data introduces a different set of risks. Combining identity documents with crypto transaction histories could allow attackers to identify digital asset holders and target them for subsequent fraud.

The next challenge for Revolut is no longer just explaining how the fake government request was approved, but whether the company can mitigate the fallout if the alleged attackers truly possess additional unreleased customer records.

Leave Reaction
Share Article
Nikolay is a cryptocurrency analyst and market writer with years of experience tracking digital asset trends and emerging blockchain technologies. A long-time crypto enthusiast, he actively trades across major exchanges and specializes in identifying early-stage projects and meme tokens. His analysis combines technical insight with a strategic, long-term investment perspective.
comment-icon Commentaries
Add your comment

Fill in necessary fields and publish