
Late last week, the British neobank and financial technology giant Revolut confirmed it was deceived into revealing private information of some of its users by attackers impersonating an undisclosed government agency.
By Sunday, September 13, the attackers had begun threatening the company with releasing information both on the firm’s customers and its internal operations unless a ransom was paid, as reported by International Cyber Digest on X.
Early on Monday, the alleged demanded payment was revealed as amounting to 10,000 Bitcoins (BTC) – worth approximately $780 million at the cryptocurrency’s press time price of $77,974 – by Coin Bureau on Elon Musk’s social media platform.
Furthermore, the attackers have reportedly accused Revolut of being negligent toward its customers and handing over personal information to countries outside its jurisdiction.
According to the screenshots of a Telegram chat allegedly showing the threatening messages, the scammers already showed the data they have on Felix Römer, CEO of the online crypto casino Gamdom, and stated: ‘Revolut demise on the way.’
‼️ BREAKING: The threat actors who targeted Revolut with information-demand emails are now posting sensitive customer data, including that of high-profile clients such as tennis player Shevchenko and Römer, CEO of Gamdom/Skinscom.
They want Revolut to pay up. They say they'll… pic.twitter.com/obuVOOABx7
— International Cyber Digest (@IntCyberDigest) September 13, 2026
How Revolut got tricked into disclosing users’ private information
Meanwhile, the neobank described the attack as ‘a sophisticated external impersonation scam’ that involved an unauthorized party sending a request email from a genuine government domain, per a September 12 TechCrunch report.
Revolut also stated that it affected a ‘limited’ number of customers and that the firm blacklisted the offending address, informed the relevant authorities and agencies, as well as the compromised users.
The attackers are believed to have a wide variety of private information, including transaction histories, account statements, verification selfies, and images of identification documents such as ID cards, as well as phone numbers and addresses.
ZachXBT, a prominent blockchain detective, also speculated that the incident primarily targeted high-net-worth individuals in his community alert on Telegram.
Revolut $200 billion IPO might be in danger after cyberattack
Lastly, the attack not only came amidst an apparent uptick in hacking attempts against various corporate entities ranging from cryptocurrency wallet makers to video game developers, but was also highly inconvenient for Revolut’s plans.
Specifically, the British neobank has been exploring the possibility of an initial public offering (IPO) in the relatively near future at a $200 billion market capitalization – significantly higher than its most recent $75 billion private valuation.
Featured image via Shutterstock