Revolut attackers demand 10,000 Bitcoin ransom after data theft involving high-net-worth users
Revolut confirmed that attackers impersonating an undisclosed government agency tricked it into disclosing private information on some users, then used that data to demand a ransom. For high-risk PSPs, the useful part is not the drama: it is the mechanism. Social engineering against compliance and support channels is enough to turn a standard information request into a customer-data incident.
- By Sunday, September 13, the attackers were threatening to release information on Revolut’s customers and internal operations unless a ransom was paid, according to International Cyber Digest on X. On Monday, the alleged demand was revealed as 10,000 Bitcoins (BTC), worth approximately $780 million at Bitcoin’s press time price of $77,974, as reported by Coin Bureau on Elon Musk’s social media platform.
- Revolut described the incident as “a sophisticated external impersonation scam” in a September 12 TechCrunch report. The company said an unauthorized party sent a request email from a genuine government domain, which is the part that matters operationally: the message did not look like obvious junk, it looked like a legitimate request coming from the right place.
- Revolut said the incident affected a “limited” number of customers. It blacklisted the offending address and informed the relevant authorities and agencies, as well as the compromised users.
- The attackers reportedly said they had data including transaction histories, account statements, verification selfies, images of identification documents such as ID cards, phone numbers, and addresses. Screenshots of a Telegram chat allegedly showed them posting sensitive customer data, including information tied to Felix Römer, CEO of the online crypto casino Gamdom, and tennis player Shevchenko.
- ZachXBT, a blockchain detective, said in a Telegram community alert that the incident appeared to target high-net-worth individuals. That is the part PSPs will read twice: if your customer base includes affluent or publicly identifiable users, the value of a successful impersonation attempt rises fast.
Revolut is also exploring an initial public offering (IPO) at a $200 billion market capitalization, up from its most recent $75 billion private valuation. The attack lands at an awkward moment, but for payment and compliance teams the broader point is simpler: any workflow that accepts external requests from trusted-looking domains needs controls that assume the sender can be fake.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!