Revolut Hackers Start Publishing Client Files, Demand 10,000 Bitcoin

ZachXBT says passports and Bitcoin histories sit among Revolut client records now being leaked daily by extortionists (Image: Shutterstock)
ZachXBT says passports and Bitcoin histories sit among Revolut client records now being leaked daily by extortionists (Image: Shutterstock)

Revolut attackers began publishing customer passports and verification selfies over the weekend, demanding payment and promising fresh leaks each day until the fintech complies.

Key Points:

  • Threat actors have begun posting Revolut customer identity documents and selfies, promising daily releases until a ransom is paid.
  • Leaked material reportedly includes passports, IBANs, withdrawal records and complete trading histories.
  • Revolut says a very limited number of customers were affected and that its systems and funds were untouched.

Revolut Leak Turns Public

The monitoring account International Cyber Digest posted on Sept. 13 that the group had stopped waiting for a payout and started dumping files on well-known account holders. The first batch included identity papers and verification selfies. The same account said the attackers had emailed Revolut with information demands before going public.

Those documents belonged to tennis player Alexander Shevchenko and Felix Römer, chief executive of the crypto gambling site Gamdom. Crypto outlets put the demand at 10,000 Bitcoin (BTC), close to $780 million at Monday's prices, though others reported that no figure had been confirmed.

Revolut declined to comment on the payment demand. Its spokesperson said core infrastructure, databases and customer accounts stayed untouched.

Also Read: XRP ETFs Hit $1.7B Record As 9-Week Inflow Streak Defies Price Weakness

ZachXBT Flags Whale Targeting

Investigator ZachXBT circulated the customer notice on Telegram. He added several categories Revolut left out of its own email, among them IBANs, withdrawal records, occupations and full Bitcoin transaction histories. He judged the breach limited in scale but aimed at wealthy account holders.

Revolut has not endorsed that reading and has not said crypto holders were singled out. Researchers warn that pairing a passport image with a complete trading history enables targeted phishing and chain analysis that starts from a real name. Identity papers and facial verification images also raise the odds of impersonation fraud against everyone named.

Revolut Breach Origin Explained

The exposure traces to a single email sent from a mailbox created inside a genuine government agency's domain, which carried valid authentication and cleared Revolut's checks. Banks must honor official agency requests, and the message read as one.

Copies of the customer notice began circulating on Sept. 12, when Revolut called the episode a sophisticated external impersonation scam and said it had alerted regulators and law enforcement.

Mark Karpelès, the former Mt. Gox chief executive, published his own notification that day. The company still has not said how many people were affected. Revolut serves more than 80 million customers across 30 countries and is running a secondary share sale that values it near $115 billion.

Read Next: Sam Altman Rules Out A 2026 OpenAI IPO And Blames AI Safety Work

Mehjabeen Arsiwala profile photo

Mehjabeen Arsiwala

Mehjabeen Arsiwala is a journalist covering crypto news, DeFi, exchanges, trading, and market analysis. Over the past three years, she has focused on the trends and narratives shaping digital asset markets, from price action and forecasts to exchange developments and on-chain signals. She specializes in clear reporting that helps readers understand what is happening in the market and why it matters.

page_article_disclaimer
page_blogs_view_latest
Show All News
Revolut Hackers Start Publishing Client Files, Demand 10,000 Bitcoin | Yellow