Revolut Breach: Attackers Demanded 10,000 Bitcoin Ransom

Revolut confirmed on 12 September 2026 that an unauthorised third party used a legitimate government agency's email domain to submit fraudulent requests for customer information, and that data was handed over as a result. "Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information," the company said in a statement first reported by TechCrunch. Revolut declined to say which agency's domain was abused.
The incident gained a sharper edge on 14 September, when The Register reported that the attackers had demanded a ransom of 10,000 Bitcoin, worth more than $782 million. The same report set out a wider picture of what was taken than the one described two days earlier. Blockchain investigator ZachXBT, who published customer notification letters sent by the bank, said the exposed records included passports and driver's licences, verification selfies, account statements, IBANs, withdrawal records and full transaction histories, alongside full names, dates of birth, home and email addresses, phone numbers and occupations.
That combination is what makes the case unusual. A leaked email address invites spam; a leaked passport scan paired with the selfie taken to verify it is the exact package used to pass identity checks at other financial institutions. Transaction histories and IBANs add a second problem: anyone holding them can reference a customer's real balance, recent payments and counterparties, which is what makes an impersonation call or message convincing. Revolut reports more than 80 million personal customers globally and more than 800,000 business accounts, though it described those caught up in the incident as "a limited number" and said only a small proportion of its customers were affected.
The method matters as much as the data. The request did not arrive through a broken system or a stolen password, but through an email domain that genuinely belonged to a government agency, using the routine channel through which banks answer official information requests. Firms that process those requests at volume have limited means to tell a forged one from a real one.
Several things remain unknown. Revolut has not published a figure for how many customers were affected, has not said whether the incident was concentrated in any particular market, and has not addressed whether the ransom was paid. The company said it blocked the email address on detection and alerted the relevant government agency, law enforcement, data protection authorities and financial regulators, and that it has contacted affected customers directly. Customers who receive such a notice should treat unsolicited calls or messages referencing their account activity with particular caution.
Sources
- The RegisterSecondary
- TechCrunchSecondary
Related
Fake IT Helpdesk Calls Defeat Passkey Logins, Microsoft Says
Sogou Flaw Let One Click Backdoor an App Used by 455M a Month
CISA Adds 5 Exploited Flaws; ScreenConnect Rated CVSS 9.9
GitLab CVSS 10.0 Flaw Exploited; CISA Deadline Is September 14
Chrome 153 Fixes 7th Exploited Zero-Day of 2026: CVE-2026-87491
Sandworm, Qilin Exploit Cisco Firewall Flaw Rated CVSS 10.0
IDScan.net Confirms Breach After 153M ID Scans Offered on Dark Web
Microsoft Fixes 2 Exploited Windows Zero-Days; CISA Sets Sept. 22
Trending now
- SB Energy files for IPO at a valuation above $50 billion
- Fake IT Helpdesk Calls Defeat Passkey Logins, Microsoft Says
- Zverev Beats Shelton in 4 Sets for First US Open Title
- VW Mission Efficiency Sets 0.158 Cd World Record
- Marvel's Wolverine Lands on PS5 With a 77 Metascore
- Saudi Pipeline Repairs to Take Weeks as Brent Tops $107
- Treasury Yield Tops 5.014%, Highest Since 2023, Then Retreats
- US Diesel Sets Record $6.23 a Gallon, AAA Figures Show
Comments
No comments yet. Be the first.