The extortion campaign against Revolut has escalated. The actors who obtained customer files through a fraudulent government data request are reportedly demanding 10,000 BTC — roughly $780 million at current prices — and threatening to publish more stolen data every day until the company pays.
The demand has not been confirmed by Revolut, and the bank has not authenticated any of the material circulating online. Multiple outlets, including Protos, Finbold and The Coin Republic, report the same figure, sourced to posts by the attackers on Telegram and X. As with everything the actors say, the number should be treated as a claim, not a fact.
Where the Campaign Stands
Recap of the mechanics, which we covered in depth when the disclosure first emerged: an unidentified third party used a legitimate government agency email domain to submit fraudulent information requests, passing Revolut's authenticity checks. The disclosed material reportedly included identity documents, verification selfies, addresses, IBANs, withdrawal records and full transaction histories — including Bitcoin activity. Revolut calls it a "sophisticated external impersonation scam," says systems and customer funds are unaffected, and has alerted the agency involved, police, data protection authorities and financial regulators.
Over the weekend the attackers moved from hoarding to publishing. Files attributed to high-profile individuals — including tennis player Alexander Shevchenko and Gamdom CEO Felix Römer, per International Cyber Digest — appeared online, with daily dumps threatened. Former Mt. Gox CEO Mark Karpelès has confirmed he was among those notified, sharing the customer notice he received. On-chain investigator ZachXBT has suggested the operation deliberately targeted a small number of wealthy customers rather than the general user base.
The attackers have also offered a justification, claiming Revolut shares customer data with governments outside its jurisdiction. That is an unverified assertion from the extortionists themselves — framing, not evidence.
Why Paying Is the Least Likely Outcome
Even taking the demand at face value, the practicalities cut against payment. A 10,000 BTC transfer would be one of the largest visible movements on the Bitcoin ledger, instantly trackable by every analytics firm and law-enforcement team watching — a point made publicly by Revolut investor and analyst Max Karpis, among others. Cashing out a sum of that size is its own operational problem.
There is also recent precedent for simply refusing. Blockstream this month declined to pay the bounty demanded by the actors holding the Liquid Network's remaining 598 BTC, leaning instead on law enforcement and forensic partners. Extortion paid is extortion funded: every successful demand finances the next campaign, which is the reason most security teams and regulators discourage payment at all.
Revolut has given no indication it intends to negotiate. The company's public position remains that a limited number of customers were affected, that they have been contacted directly, and that the police investigation is ongoing.
What the Data Enables Next
The core risk was never the leak itself but what the files connect: verified legal name, face, home address, IBAN and Bitcoin transaction history in a single package. For the affected population — apparently skewed toward wealthy crypto users — that is the raw material for targeted impersonation calls that cite genuine withdrawals and real addresses, and for physical-security risks of the kind that has already touched crypto holders in Europe. Anyone who transacted meaningful sums through a single regulated venue should assume their exposure profile is knowable, and act accordingly.
TrustGrade tracks the security posture of fintechs, exchanges, and protocols. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.