Revolut Extortionists Begin Leaking Customer Bitcoin (BTC) Records, Threaten Daily Drops

Hackers holding Revolut customer data, including Bitcoin (BTC) transaction histories, demand ransom and threaten daily leaks as the ICO reviews the breach.

(05:17 PM UTC)
4 min read
AI SummaryAI
  • Revolut extortionists began publishing customer files and threaten daily releases via Telegram.
  • Leaked records include passports, verification selfies, IBANs and full Bitcoin transaction histories.
  • Claimed customer data began circulating on X and Telegram from September 13.
  • Mt. Gox CEO Mark Karpelès confirmed he was affected by the data breach.
k7rq2fdm

Ransom Demands and Daily Leaks

Fresh extortion demands have thrown Revolut's handling of customer data — and the Bitcoin transaction histories inside it — into a fast-moving security crisis. A group calling itself “Revolut Smilik” has confirmed to reporters that it is demanding payment from the fintech, and has warned over Telegram that it will release an escalating volume of stolen files “every day” if the company refuses to pay. Files the attackers claim belong to affected customers, including identity documents tied to some public figures, have been circulating on X and Telegram since September 13. Revolut has declined to state how many customers are exposed and has not said whether it will negotiate.

The confrontation stems from an unusual admission by the company: an unauthorized third party submitted records requests from an email account hosted on a legitimate government agency's own domain, and Revolut accepted them as genuine, handing over identity files, account statements and, in some cases, complete Bitcoin transaction histories. The company has characterized the episode as a sophisticated external impersonation scam rather than a direct database breach, stressing that its core infrastructure, databases and customer funds were never compromised. It says it blocked the fraudulent address once the deception was uncovered and reported the matter to government agencies, law enforcement, data-protection authorities and financial regulators, while maintaining that only a “very limited” number of customers were affected. In other words, a misdirected disclosure has now hardened into a second-stage extortion operation with a publication schedule. The UK Information Commissioner's Office has confirmed receipt of Revolut's incident report and is assessing the material — a regulator record that will shape how the case is treated under British data-protection law. What remains undisclosed is equally significant: the number of victims, the identity of the impersonated agency, and the size of the ransom demand.

Passports, Selfies and Trading Histories

The sensitivity of what left Revolut's systems is what pushes this case well past a routine email dump. A customer notification circulating online lists names, dates of birth, postal and email addresses, phone numbers, copies of passports and driver's licenses, identity-verification selfies, account statements, IBANs, withdrawal records and complete trading histories — with Bitcoin activity explicitly named. Mt. Gox CEO Mark Karpelès, who shared the notice, confirmed he was among those affected. On-chain investigator ZachXBT flagged the incident on Saturday and suggested it appears aimed at high-net-worth users — crypto whales in industry parlance — although Revolut has not confirmed whether the victims were concentrated among wealthier clients, and on-chain data alone cannot yet establish a pattern.

The exposure also amplifies concerns around wrench attacks, in which criminals who know a holder's real name, home address and apparent balances resort to physical coercion rather than digital trickery. The failure mode itself is instructive: hardware wallet maker Trezor disclosed a structurally similar problem last week, when a breach at its email provider let attackers send phishing messages from its own domain — days after a ShipMonk breach exposed another 67,000 of its US customers. The stakes for Revolut are considerable. The company, which serves more than 80 million customers, won conditional approval from the US Office of the Comptroller of the Currency this month to establish a national bank, began rolling out its EURR euro stablecoin across Denmark, Poland and Portugal in August, and is reportedly weighing a listing that could value it as high as $200 billion — a trust-sensitive moment for a firm positioning itself as a regulated banking bridge between fiat and crypto.

ICO Review and Unanswered Questions

For the broader Bitcoin ecosystem, the episode is a blunt reminder that on-chain pseudonymity is only as strong as the weakest KYC archive. Our reading: this was not a replay attack or any other ledger-level failure — no keys were stolen and no consensus rule was broken — but an institutional lapse in verifying that a government-channel request was genuine. With the UK regulator still assessing the report and Revolut withholding the victim count, ransom size and agency name, the Information Commissioner's findings will be the first authoritative record of the blast radius. Coins held long term under a classic HODL strategy in self-custody sit outside any platform's data warehouse — a consideration worth weighing when deciding how much identity data to keep with centralized platforms, from fintech apps to the best crypto exchanges.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.