The “Revolut hackers demand 10,000 Bitcoin” story began with no hack at all. On September 12, 2026, the British fintech confirmed that it had handed sensitive customer records to an unauthorized third party — not because attackers broke into its systems, but because they emailed Revolut from a legitimate government agency domain and asked. Roughly 680 customers lost their passports, verification selfies, IBANs, and full transaction histories, including complete Bitcoin records. A group calling itself Revolut Smilik is now publishing dossiers daily on Telegram and demanding a 10,000 BTC ransom — roughly $780 million at current prices.
The breach was not a technical failure in the conventional sense. No malware, no exploited vulnerability, no stolen credentials. The attackers obtained something better: authenticated access to a genuine government mailbox, which let their fraudulent data requests pass the email authentication checks that most organizations treat as proof of legitimacy. Revolut’s compliance staff processed the requests as genuine government demands and released the records.
That distinction matters more than the headline. A fintech that stores its customers’ passports, faces, and crypto balances for anti-money-laundering compliance just demonstrated that the weakest link in that chain is the intake process for legal requests — and the timing, weeks into a US banking charter approval and months into a $115 billion valuation, could hardly be worse.
What Happened: The Verified Timeline
The incident unfolded over five days, and the escalation pattern is instructive.
On September 11, Revolut began notifying a “limited” set of customers that their data had been disclosed to an unauthorized party. On September 12, the company publicly confirmed what it called “a sophisticated external impersonation scam,” notified regulators and law enforcement, and stressed that “Revolut systems and customer funds are unaffected.” Then, on September 13 and 14, the attackers changed the game: they began publishing customer dossiers on a Telegram channel, one file at a time, promising more every day. By September 15, the Financial Times and City AM had established the scale — approximately 680 affected customers across multiple countries — and a threat group calling itself Revolut Smilik had set its price: 10,000 Bitcoin.
The data released is unusually sensitive even by breach standards. According to customer notifications reviewed by TechCrunch and shared publicly by blockchain investigator ZachXBT, the exposed records include full names, dates of birth, postal and email addresses, and phone numbers. They also include whatever identity document each customer submitted at onboarding — passport or driver’s licence — plus the verification selfie taken through the app. The financial exposure goes further: account statements, IBANs, withdrawal records, and complete transaction histories, including every Bitcoin transaction. Payment card numbers and private crypto keys were not included, according to reports of the notifications.
Victims are not Random
The victims are not random. Leaked samples reviewed by multiple outlets include business leaders, sports professionals, and performing artists. Tennis player Alexander Shevchenko and Felix Römer, CEO of crypto gambling site Gamdom, are among the named victims; Römer confirmed the data came from Revolut. Former Mt. Gox chief Mark Karpelès said Revolut warned him his information was exposed. The geographic breakdown, as of September 15: 12 customers in Ireland, 25 in Spain, and 27 in Romania, with additional countries still being mapped.
Why the Timing Could Hardly Be Worse
To understand the stakes, consider where Revolut stood in the nine days before the breach became public.
On July 22, 2026, Revolut reached a $115 billion valuation in a secondary share sale — up 53 percent in a year, making it one of the largest privately held companies in the world and Europe’s first “centicorn.” The sale priced its shares at $2,017 each and made founder Nik Storonsky worth more than $36 billion on paper. The company surpassed 80 million customers and is targeting 100 million by mid-2027.
Then, on September 3, 2026 — nine days before the breach disclosure — the US Office of the Comptroller of the Currency granted Revolut conditional approval for a national bank charter. The approval clears a path for a Stamford, Connecticut-based Revolut Bank US to launch in 2027 with direct access to Federal Reserve payment systems, ending its reliance on partner Lead Bank. But it comes with conditions: a minimum $95 million in initial paid-in capital, a 10 percent Tier 1 leverage ratio for three years, separate sign-offs for four higher-risk business lines, and an 18-month expiration clock.
Crucially, the charter is not final. The FDIC deposit-insurance application is under review, and the Federal Reserve must approve Revolut’s holding-company applications — a review that, as reported, will cover Revolut’s compliance record across its global operations. A breach whose root cause is a compliance-process failure now sits squarely inside that review window. The same week, the UK’s Information Commissioner’s Office confirmed it is assessing the incident, the Financial Conduct Authority is engaging with the company, and Ireland’s Data Protection Commission may open a parallel inquiry.
The Attack: Emergency Data Request Fraud, Explained
Moving to the mechanics, the attack class here has a name and a documented history.
An Emergency Data Request is a mechanism that lets law enforcement ask a platform for user data without a warrant when there is an imminent risk of death or serious harm — a kidnapping, a suicide threat, a terrorism investigation. Platforms process EDRs on an emergency timeline, often within hours, which is precisely the point. The urgency is designed for genuine emergencies. It also makes EDRs ideal social-engineering vectors, because the time pressure discourages the verification steps that would expose a forgery.
The fraud technique itself dates to at least 2022, when Krebs on Security documented criminals compromising police email accounts and sending unauthorized EDRs to internet providers, phone companies, and social media platforms. In 2021 and 2022, Apple and Meta both disclosed that they had handed user data to hackers impersonating law enforcement officers through forged emergency requests. By November 2024, the FBI’s Internet Crime Complaint Center was warning of a spike in compromised police email accounts used to submit fraudulent legal process — noting that criminals openly trade access to government mailboxes, and advising companies to apply “critical thinking” to any emergency request and verify it with the originating agency through independently obtained contact details.
The volume context explains why this keeps working. Meta alone received roughly 46,400 emergency disclosure requests globally in the first half of 2025 — about 258 per day — and emergency disclosures have grown from about 3 percent of US government requests to Facebook in 2013 to about 5 percent by 2026. Every one of those requests arrives with urgency built in. Forged ones blend into that traffic unless an organization verifies them out-of-band.
Why Revolut Fell for It
The requests sent to Revolut came from a genuine government agency domain, and they passed the standard email authentication checks — SPF and DKIM. Those protocols prove the message really came from that domain. They say nothing about whether the person sending it is authorized to make the request, or whether the account itself has been compromised. Revolut staff processed the requests through its compliance workflow and released the records.
A single control would likely have stopped the fraud: a callback to the agency’s published phone number, independent of any contact details supplied in the request itself. Security guidance on EDR fraud from the FBI and independent researchers recommends exactly this. According to the reporting so far, that verification step was absent — and that gap, not any technical vulnerability, is the story.
The Ransom Math: Why “Revolut Hackers Demand 10,000 Bitcoin” Is Theater
Here the story takes an analytical turn the coverage has mostly skipped.
Ten thousand Bitcoin is roughly $780 million. Spread across 680 customers, that is about $1.15 million per exposed dossier — an absurd price for data whose primary harm is identity fraud and targeted phishing, not direct financial theft. No organization is known to have ever paid a ransom approaching that size; even the largest documented corporate ransom payments run one to two orders of magnitude lower. Revolut’s entire annual profit, by comparison, is a fraction of the demand.
The number is the message. The attackers are not pricing a transaction; they are maximizing pressure and headlines. The daily leaks do the real damage — each published dossier de-anonymizes a named individual’s full financial and crypto history, and the group is timing the releases to keep the story alive. For a company nine days into the most consequential regulatory approval of its life, that reputational drip is the actual weapon. The Bitcoin figure functions as a taunt: pay us, or stay in the news.
There is also a crypto-specific angle that makes this breach different from a typical KYC leak. Bitcoin is pseudonymous, not anonymous. Pairing verified identity documents with complete Bitcoin transaction histories strips that pseudonymity away — anyone holding the leaked dossiers can connect real names, faces, and passports to wallet activity and balances. For the high-net-worth individuals among the 680, the elevated risk is not just phishing but targeted extortion and physical security threats. The extortion campaign can credibly cite real balances and real trades.
What’s Verified vs. What’s Unconfirmed
An honest audit of the record separates what has been confirmed from what remains claim, speculation, or reporting shorthand.
The breach and its mechanism — Verified. Reuters, TechCrunch, and The Register all confirmed the government-domain email fraud, and ZachXBT published the customer notifications. Revolut’s own statement confirms the impersonation scam framing.
The 680-customer figure — Verified with attribution. Revolut has never said “680” publicly; the company’s official language is “very limited” and “a limited number of customers.” The figure comes from Financial Times reporting and was confirmed to City AM by a source close to the bank. The per-country breakdowns (Ireland 12, Spain 25, Romania 27) come from national outlets RTÉ, El Español, and Profit.ro respectively.
The ransom and daily leaks — Verified as claims. The 10,000 BTC demand and the daily-leak threat are established by the attackers’ own Telegram posts and multiple outlets’ reviews of the leaked material. Revolut has not confirmed payment, and there is no indication any payment has been made.
“Six months of access” — Unconfirmed. Some reporting references a hacker claim of six months of access to the fraudulent channel. Revolut has said only that it “recently identified” the scam. Treat the six-month figure as unverified attacker boasting.
Which government agency was involved — Withheld. Revolut has declined to name the jurisdiction or the agency whose domain was used, which also leaves open whether the mailbox was compromised, purchased from a credential market, or abused by an insider. This is the single most consequential unknown in the case.
Valuation, charter, and history — Verified. The $115 billion secondary sale (July 2026), OCC conditional approval (September 3, 2026), and the 2022 Revolut breach affecting roughly 50,150 customers via a third-party supplier all verify across multiple outlets.
The Questions That Weren’t Answered
Beyond the unknowns above, several questions deserve answers that neither Revolut nor the coverage has provided.
Why did a company built on compliance lack out-of-band verification? Revolut’s entire KYC operation exists because regulators demand document verification. The same rigor was not applied to verifying who was asking for the documents. Was there a dual sign-off requirement before releasing identity documents? If yes, why did it fail? If no, why not?
Was the GDPR 72-hour clock met? UK GDPR requires breach notification to the ICO within 72 hours of awareness where risk to individuals exists. Customers were notified September 11 and the ICO is assessing — but the awareness date, and whether documentation obligations were met, has not been disclosed.
Will Revolut compensate the 680? The company has not announced identity-protection services, credit monitoring, or document replacement support. For victims whose passports and faces are now on Telegram, that omission is itself information.
Does this affect the Fed’s holding-company review? The Federal Reserve’s review covers Revolut’s global compliance record. An ICO assessment of a compliance-process failure is exactly the kind of finding that review is designed to surface. Nobody on any side of the transaction has addressed this.
Why was the payout so rich? A single fraudulent request channel yielded full KYC packs plus Bitcoin histories for 680 customers. Did the attackers make one request or many? Over what period? The scope of the disclosure — full histories, not just identity fields — suggests either an unusually broad request that was never challenged, or multiple requests that no one aggregated and flagged as anomalous.
What This Means for You
The implications sort cleanly by audience.
If you were affected: Treat your passport or driver’s licence and selfie as permanently compromised. Check the Revolut app for the official notice rather than clicking any emailed link. Change your password, review active sessions and beneficiaries, and enable alerts. In the UK, consider Cifas Protective Registration and a Notice of Correction on your credit file; elsewhere, place fraud alerts with credit bureaus. If you hold Bitcoin through Revolut, assume your wallet activity is known to criminals — any contact referencing your real balances or past trades is a credible social-engineering attempt, not a coincidence.
If you run compliance or security at a fintech: Audit your government-request intake this week. The controls are known and cheap relative to the exposure: route requests through a registered law-enforcement portal rather than plain email; require a callback to the agency’s published number for every emergency request; require dual authorization before releasing identity documents or full account histories; log every request with timestamps and scope; flag anomalies such as unusual jurisdictions, urgent language, or bulk data demands; and release the minimum data the request actually supports. Uber, Meta, Google, Apple, and Microsoft already run portal-based intake — the standard exists, and Revolut’s failure shows the cost of not meeting it.
Crypto on KYC Platform
If you hold crypto on any KYC platform:
This breach is the proof of concept for a risk that has always been theoretical. The pairing of on-chain pseudonymity with verified identity in a single leak. Diversifying custody and assuming transaction histories are leakable is now reasonable hygiene, not paranoia.
If you watch Revolut as an investor or competitor:
The breach, in fact, will not sink a $115 billion company. But it lands on every front that matters at once. Like, for instance, The ICO assessment, the FCA engagement, the Fed’s compliance review. And an IPO-adjacent narrative built on operational excellence at global-bank scale. The 680 customers are, actually, 0.00085 percent of the base; the compliance-process failure is the real product defect. Watch for the ICO’s findings, any Fed commentary, and whether Revolut publishes its EDR-verification reforms. How quickly it hardens this specific process — and says so publicly. This, in fact, s the signal that separates a contained incident from a pattern.

Editor’s Note
This article draws on two research drafts supplied in September 2026 and independently verifies their principal claims. The breach record comes from these. From Reuters (September 12, 2026). From TechCrunch (September 12, 2026). The Register (September 14, 2026, citing customer notifications shared by ZachXBT), Cointelegraph (September 13, 2026). Computing (September 15, 2026). The Crypto Times (September 15, 2026, citing the Financial Times, City AM, RTÉ, El Español, and Profit.ro). From crypto.news (September 15, 2026). And Coinlive (September 14, 2026). The 680-customer figure originates with Financial Times reporting and a confirmation to City AM. Revolut’s official statements use “very limited” without a number.
Valuation and charter context comes from various sources. From Reuters, Bloomberg Law, Banking Dive (September 3–4, 2026). From CoinDesk and Yahoo Finance (July 22, 2026), and TechTimes (September 4, 2026). EDR fraud history comes from these. From Krebs on Security (March 2022 and November 2024). From The Verge (March 2022), TechCrunch’s FBI coverage (November 8, 2024). The FBI IC3 public service announcement (November 2024). And Meta transparency report data as analyzed by Data Explained (March 2026). And businessstats.com (May 2026) — including roughly 46,400 emergency disclosures globally in H1 2025. The 2022 Revolut breach affecting approximately 50,150 customers via a third-party supplier is drawn from contemporaneous reporting.
The drafts’ claim of 85,600 emergency disclosure requests in 2026 (up 28.2 percent) could not be verified. And has been replaced with the verifiable Meta figures. What remains uncertain is a lot. The government agency whose domain was used. Whether its mailbox was compromised or purchased. The duration of the fraud before detection. The hacker claim of six months of access. nd whether Revolut has offered remediation to affected customers.

