Revolut Attackers Reportedly Demand 10,000 BTC in Ransom
Key Takeaways
- •Revolut confirmed limited exposure of customer information but said its systems and customer funds were unaffected.
- •Potentially exposed records included identity details, account statements, IBANs, withdrawal records and transaction histories involving Bitcoin.
- •Coin Bureau reported an alleged 10,000 BTC ransom demand, but Revolut and law enforcement had not verified the claim.
- •Social-media posts alleging that customer records were released do not independently confirm the material’s source or authenticity.
- •The exposed information could support targeted phishing or impersonation, so unexpected account-related requests should be checked through Revolut’s official app.

Revolut confirms limited customer-data exposure
Revolut has confirmed that a limited amount of sensitive customer information was exposed after an unauthorised third party used an email account on a legitimate government-agency domain to send fraudulent requests for customer data. The company said the affected group was “very limited,” that it had notified customers, and that its systems and customer funds were not affected, according to a Reuters report.
The potentially disclosed information included names, dates of birth, postal and email addresses, telephone numbers, passports and driving licences. A customer notice reported by The Block also listed account statements, IBANs, withdrawal records and transaction histories, including Bitcoin transactions.
The exposure of transaction history alongside real identities could make follow-up phishing attempts more convincing. A criminal who knows a customer’s name, contact details and previous Bitcoin activity could tailor a message to appear more credible than a generic scam. An earlier Coindoo report examined that risk.
The company’s statement distinguishes the reported exposure of customer information from access to Revolut systems or customer funds. That means the immediate concern described in the available reporting is the possible misuse of personal and account data, rather than a confirmed theft of funds. The alleged ransom claims and any further disclosures therefore need to be assessed separately from Revolut’s confirmation of the data exposure.
Coin Bureau reports an alleged 10,000 BTC demand
Coin Bureau said in a post on X that the group behind the Revolut incident was demanding 10,000 BTC and threatening to leak stolen customer data. The post included an image described as redacted KYC material linked to Felix Römer, who the post identified as the CEO of Gamdom and Skinscom.
Neither Revolut nor law enforcement had publicly verified the alleged ransom demand or the origin of the material shown in the post as of the time of writing. Coin Bureau’s post said:
🚨BREAKING: Revolut attackers demand 10,000 BTC ransom, threatening to leak stolen customer data. The threat actors who allegedly tricked Revolut into handing over sensitive customer data by posing as a government are now publishing information belonging to high-profile clients.… pic.twitter.com/5IIaCHHOYT — Coin Bureau (@coinbureau) September 14, 2026
The post is also available through Coin Bureau’s X account.
Posts allege that customer records have been released
International Cyber Digest posted on X that the threat actors had begun publishing sensitive customer information and were threatening additional releases. Its post included screenshots said to show customer material, but the screenshots do not independently establish the source or authenticity of the records.
The post was followed by a similar claim from Evan Luthra, who shared an image described as redacted customer material and alleged that the group had demanded payment. Luthra wrote:
🚨THINGS ARE GETTING UGLY FOR REVOLUT!!! The group targeting the company has started leaking alleged customer data tied to high-profile clients. Now they’re demanding payment and threatening to dump more private messages, customer records and internal information. They’re also… pic.twitter.com/xyfkedn3bg — Evan Luthra (@EvanLuthra) September 13, 2026
The post is also available through International Cyber Digest’s X post and Evan Luthra’s X account.
The alleged releases could be intended to lend weight to the payment demand by showing that the group has access to sensitive records. Publishing material said to belong to real customers could create further harm without giving the attackers access to customer funds. If the material is authentic, additional publication could expose more people to fraud.
There is no verified evidence that the group has sold the Revolut data or plans to do so. However, criminals could attempt to use or distribute customer datasets for phishing and impersonation. Identity documents, account records and previous Bitcoin activity could be used to tailor an approach to a particular customer.
Risk of targeted follow-up scams
Revolut has confirmed that sensitive customer information was disclosed, while the alleged ransom demand and the public release of specific records remain unverified. For potentially affected users, the practical risk is a more targeted form of fraud: a message or call that uses genuine personal or transaction details to appear legitimate.
Any unexpected request concerning a Revolut account or Bitcoin activity should be checked through the official Revolut app rather than through a link or telephone number supplied by the sender. The original report was published by Coindoo.
This article is provided for informational purposes only and does not constitute legal, financial or cybersecurity advice.