Revolut Hackers Reportedly Demand 10,000 BTC Ransom

Posts on X claim that the group behind Revolut’s recent customer-data exposure is seeking 10,000 BTC and threatening to release more records. Revolut has not confirmed the alleged demand.
Key Takeaways
- Revolut confirmed a limited data exposure.
- Customer funds were not affected, Revolut said.
- Posts claim selected customer records were released.
- Bitcoin histories can strengthen targeted scams.
Coin Bureau reports a 10,000 BTC ransom demand
Coin Bureau posted on X that the group behind the Revolut incident was demanding 10,000 BTC while threatening to leak stolen customer data. Its post included an image said to show redacted KYC material linked to Felix Römer, described in the post as the CEO of Gamdom and Skinscom.
Neither Revolut nor law enforcement has publicly verified the claimed demand or the origin of the material shown in the post as of time of writing
🚨BREAKING: Revolut attackers demand 10,000 BTC ransom, threatening to leak stolen customer data.
The threat actors who allegedly tricked Revolut into handing over sensitive customer data by posing as a government are now publishing information belonging to high-profile clients.… https://t.co/kJi58fAHaa pic.twitter.com/5IIaCHHOYT
— Coin Bureau (@coinbureau) September 14, 2026
Revolut says a fake government request obtained customer data
Revolut said an unauthorised third party used an email account on a legitimate government-agency domain to send fraudulent requests for customer information. The company described the affected group as “very limited,” said it had notified customers, and stated that its systems and customer funds were unaffected, according to a Reuters report.
The information potentially disclosed included names, dates of birth, postal and email addresses, telephone numbers, passports and driving licences. A customer notice reported by The Block also listed account statements, IBANs, withdrawal records and transaction histories, including Bitcoin transactions.
Our earlier report on Revolut’s exposure of Bitcoin activity through a fake request examined the risk created when transaction history is tied to a real identity. A criminal who knows a customer’s name, contact details and past Bitcoin activity can write a phishing message that looks far more credible than a generic scam.
Posts allege that customer records are being released
International Cyber Digest posted on X that the threat actors had begun publishing sensitive customer information and were threatening further releases. Its post included screenshots said to show customer material, but those screenshots do not independently establish their source or authenticity.
International Cyber Digest’s post was followed by a similar claim from Evan Luthra, who shared an image said to show redacted customer material and alleged that the group had demanded payment.
🚨THINGS ARE GETTING UGLY FOR REVOLUT!!!
The group targeting the company has started leaking alleged customer data tied to high-profile clients.
Now they’re demanding payment and threatening to dump more private messages, customer records and internal information.
They’re also… https://t.co/1rPcqLVb0H pic.twitter.com/xyfkedn3bg
— Evan Luthra (@EvanLuthra) September 13, 2026
The alleged releases appear designed to give the payment demand weight. By publishing material said to belong to real customers, the group can try to show that it has access to sensitive records and can cause further harm without accessing customer funds. If the material is authentic, additional publication could expose more people to fraud. Criminals may also try to use or distribute customer datasets for phishing and impersonation, although there is no verified evidence that this group has sold the Revolut data or plans to do so.
That changes what affected users should look for after the breach. Identity documents, account records and previous Bitcoin activity can be used to tailor an approach to a particular customer.
How a follow-up crypto scam may look
The threat now extends beyond the original disclosure
Revolut has confirmed that sensitive customer information was disclosed, while the alleged ransom and public release of records remain unverified. For users who may have been affected, the practical risk is a more targeted form of fraud: a message or call that uses genuine personal or transaction details to appear legitimate. Any unexpected request about a Revolut account or Bitcoin activity should be checked through the official app, not through a link or contact number supplied by the sender.
This article is provided for informational purposes only and does not constitute legal, financial or cybersecurity advice.









