Industry News

Revolut Hit by Fake Government Request, Attackers Demand $780M in Bitcoin

Blockonomi · 15 Sept 2026
Key Takeaway Always independently verify the identity and authority of anyone requesting customer data, even if the request appears to come from a government body, before disclosing any information.

Digital bank Revolut has confirmed a data breach affecting around 680 customers after attackers impersonated a government authority using a compromised, genuine-looking official email account. Believing the request to be legitimate, Revolut handed over sensitive customer data including passport details, banking account identifiers, home addresses, verification selfies, government ID scans and Bitcoin transaction records.

The attackers are now attempting to extort Revolut, demanding 10,000 Bitcoin (roughly $780 million) and threatening to publish the stolen data if the ransom is not paid. Researchers say the attack appears targeted at wealthy account holders, and information belonging to high-profile individuals, including a cryptocurrency executive and a former exchange CEO, has reportedly already begun to appear online.

The incident highlights how convincing impersonation of official channels can bypass normal verification processes, even at large financial institutions. Attackers are increasingly exploiting trust in government-style requests to extract sensitive data before pivoting to extortion.

Summarised by CISO AI from Blockonomi. We link back to every original so you can read it yourself.