{"id":657231,"date":"2026-09-14T09:15:31","date_gmt":"2026-09-14T09:15:31","guid":{"rendered":"https:\/\/www.crypto-news-flash.com\/?p=1302864"},"modified":"2026-09-14T09:15:31","modified_gmt":"2026-09-14T09:15:31","slug":"revolut-faces-a-780m-ransom-over-a-breach-without-a-hack","status":"publish","type":"post","link":"https:\/\/e-bitco.in\/index.php\/2026\/09\/14\/revolut-faces-a-780m-ransom-over-a-breach-without-a-hack\/","title":{"rendered":"Revolut Faces a $780M Ransom Over a Breach Without a Hack"},"content":{"rendered":"<div class=\"eth-editorial-banner\"> <img decoding=\"async\" class=\"eth-editorial-logo\" src=\"https:\/\/www.crypto-news-flash.com\/wp-content\/uploads\/2025\/11\/cnf2-scaled-1-1-1.png\" alt=\"Crypto News Flash\"> <span class=\"eth-editorial-text\">All news is rigorously fact-checked and reviewed by leading blockchain experts and seasoned industry insiders.<\/span> <\/div>\n<ul>\n<li><strong>Attackers reportedly demand 10,000 BTC, worth about $780 million.<\/strong><\/li>\n<li><strong>Revolut confirms customer data was disclosed, but says systems and funds remain secure.<\/strong><\/li>\n<li><strong>Exposed records may include identity documents and Bitcoin transaction histories.<\/strong><\/li>\n<li><strong>The incident exploited government-request verification rather than Revolut\u2019s core systems.<\/strong><\/li>\n<\/ul>\n<p>Attackers linked to <strong><a href=\"https:\/\/www.crypto-news-flash.com\/bitcoin-transaction-histories-exposed-in-revolut-data-incident\/\">Revolut\u2019s customer data exposure<\/a><\/strong> are reportedly demanding 10,000 BTC, worth roughly $780 million, after beginning to publish information allegedly belonging to high-profile clients. Revolut has confirmed the underlying disclosure but has not verified the ransom demand or authenticated the material being released by the threat actors.<\/p>\n<h2>Attackers Put a $780 Million Price on the Stolen Data<\/h2>\n<p>The extortion attempt emerged after the group claiming responsibility began publishing records it says belong to Revolut customers and threatening further releases.<\/p>\n<p><a href=\"https:\/\/finance.yahoo.com\/markets\/crypto\/articles\/revolut-customer-records-exposed-attackers-093827065.html\" target=\"_blank\" rel=\"noopener\"><strong>According to Yahoo Finance<\/strong><\/a>, the attackers are reportedly demanding 10,000 BTC and have threatened to publish additional customer information each day until payment is made. The ransom figure remains an attacker claim rather than a confirmed demand acknowledged by Revolut or law enforcement.<\/p>\n<p>The group has also accused Revolut of negligence in protecting customer privacy and alleged that sensitive information was supplied to countries outside appropriate jurisdictions. Those allegations have not been independently established.<\/p>\n<p>What is confirmed is the earlier disclosure that gave an unauthorized party access to unusually sensitive financial and identity information.<\/p>\n<h2>An Authentication Scam, Not a Core System Breach<\/h2>\n<p>Revolut says the incident began when an unauthorized party submitted fraudulent information requests using an email account operating from a legitimate government agency domain.<\/p>\n<p>The requests appeared authentic, leading Revolut to provide customer information before discovering the deception. The company has characterized the incident as a sophisticated external impersonation scam rather than an intrusion into its banking infrastructure.<\/p>\n<p>After identifying the unauthorized request, Revolut blocked the email address and notified the government agency involved, law enforcement, data protection authorities and financial regulators.<\/p>\n<p>The company has not identified the agency or disclosed an exact number of affected customers, describing the group as limited. Revolut also said its systems and customer funds were unaffected.<\/p>\n<p>The control failure sits in the process used to authorize disclosure of financial records. A request can originate from authentic government infrastructure without proving that the individual behind it has authority to obtain a particular customer\u2019s information.<\/p>\n<p>That means financial institutions handling government demands need to verify more than the sender\u2019s technical credentials. The requesting official, jurisdiction, legal basis and scope of the information sought are separate controls.<\/p>\n<h2>Why KYC Plus Bitcoin History Heightens Risk<\/h2>\n<p>The potential data exposure extends considerably beyond contact information.<\/p>\n<p>According to notices sent to affected customers, records may include names, dates of birth, occupations, postal addresses, email addresses, telephone numbers and copies of passports or driver\u2019s licenses. Verification selfies may also have been disclosed.<\/p>\n<p>Financial records potentially include account statements, IBANs, withdrawal information and complete transaction histories, including Bitcoin activity. Revolut said biometric facial telemetry was not compromised, distinguishing the underlying verification image from biometric data derived from it.<\/p>\n<p>Former Mt. Gox CEO <strong><a href=\"https:\/\/x.com\/MagicalTux\/status\/2099087920280035556\" target=\"_blank\" rel=\"noopener\">Mark Karpel\u00e8s said publicly<\/a><\/strong> that he was among the affected customers and shared material from the notification he received.<\/p>\n<p>Onchain investigator ZachXBT, who helped bring wider attention to the incident, said the exposure appeared limited in size but seemed to have targeted high-net-worth users. Revolut has not confirmed that assessment.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Idk why I am blocked by both Revolut accounts. <a href=\"https:\/\/t.co\/wLd3IdmSF9\">pic.twitter.com\/wLd3IdmSF9<\/a><\/p>\n<p>\u2014 ZachXBT (@zachxbt) <a href=\"https:\/\/x.com\/zachxbt\/status\/2098665718850220042?ref_src=twsrc%5Etfw\">September 12, 2026<\/a><\/p>\n<\/blockquote>\n<p>The combination of identity and financial records creates a particular problem for crypto holders.<\/p>\n<p>Bitcoin transactions are publicly observable, but blockchain addresses do not inherently disclose the legal identity or residential address of the person behind them. Records connecting transaction histories with passports, names and physical addresses can remove part of that separation.<\/p>\n<p>For an attacker, the resulting dataset can also make impersonation significantly more convincing. A fraudulent caller who already knows a victim\u2019s identity, banking information and previous transactions can construct a highly personalized approach without needing access to the victim\u2019s Revolut account.<\/p>\n<h2>The Broader Industry Failure<\/h2>\n<p>The longer-term issue now extends beyond the ransom attempt.<\/p>\n<p>Financial institutions routinely process requests from law enforcement agencies, regulators and other government authorities. The Revolut incident demonstrates the weakness that emerges when a trusted communication channel becomes part of the attack itself.<\/p>\n<p>That is particularly relevant because conventional email security controls are designed primarily to establish whether a message originates from authorized infrastructure. Revolut\u2019s customer notice indicated that the fraudulent request came from within the real government domain and carried genuine authentication credentials.<\/p>\n<p>The next meaningful disclosure will therefore be what Revolut changes in its government-request verification process.<\/p>\n<p>Secondary confirmation with the requesting authority, independent validation of the official making the request and tighter jurisdictional checks could become more important when a demand involves passports, residential addresses and complete financial histories.<\/p>\n<p>For other banks, exchanges and fintech companies, the incident also raises a practical question: whether requests previously received from the same government infrastructure should be reviewed once the affected agency is identified.<\/p>\n<p>That could ultimately determine whether Revolut encountered an isolated fraudulent request or exposed a method capable of being used against other financial institutions.<\/p>\n<h2>Actionable Steps for Affected Revolut Users<\/h2>\n<ul>\n<li><strong>Verify contacts in-app:<\/strong> Never trust phone numbers, contact details or links contained in unexpected messages. Confirm unusual requests directly through the official Revolut app.<\/li>\n<li><strong>Protect authentication credentials:<\/strong> Never provide passwords, authentication codes or wallet seed phrases in response to unsolicited contact. Genuine personal information in a message does not make the sender legitimate.<\/li>\n<li><strong>Beware of personalized scam attempts:<\/strong> A caller who knows your address, banking details or previous Bitcoin transactions is not automatically verified as Revolut or law enforcement. The exposed information itself can be used to make impersonation attempts appear credible.<\/li>\n<\/ul>\n<p> <a href=\"https:\/\/www.crypto-news-flash.com\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>All news is rigorously fact-checked and reviewed by leading blockchain experts and seasoned industry insiders. Attackers reportedly demand 10,000 BTC, worth about $780 million. Revolut confirms customer data was disclosed, but says systems and funds remain secure. Exposed records may include identity documents and Bitcoin transaction histories. The incident exploited government-request verification rather than Revolut\u2019s [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":657232,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[25],"class_list":{"0":"post-657231","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-other","8":"tag-news"},"_links":{"self":[{"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/posts\/657231","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/comments?post=657231"}],"version-history":[{"count":0,"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/posts\/657231\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/media\/657232"}],"wp:attachment":[{"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/media?parent=657231"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/categories?post=657231"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/e-bitco.in\/index.php\/wp-json\/wp\/v2\/tags?post=657231"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}