Coin Bureau posted on X that the group behind the Revolut incident was demanding 10,000 BTC while threatening to leak stolen customer data. Its post included an image said to show redacted KYC material linked to Felix Römer, described in the post as the CEO of Gamdom and Skinscom.
Neither Revolut nor law enforcement has publicly verified the claimed demand or the origin of the material shown in the post as of time of writing
🚨BREAKING: Revolut attackers demand 10,000 BTC ransom, threatening to leak stolen customer data.
The threat actors who allegedly tricked Revolut into handing over sensitive customer data by posing as a government are now publishing information belonging to high-profile clients.… https://t.co/kJi58fAHaa pic.twitter.com/5IIaCHHOYT
— Coin Bureau (@coinbureau) September 14, 2026
Revolut said an unauthorised third party used an email account on a legitimate government-agency domain to send fraudulent requests for customer information. The company described the affected group as “very limited,” said it had notified customers, and stated that its systems and customer funds were unaffected, according to a Reuters report.
The information potentially disclosed included names, dates of birth, postal and email addresses, telephone numbers, passports and driving licences. A customer notice reported by The Block also listed account statements, IBANs, withdrawal records and transaction histories, including Bitcoin transactions.
Our earlier report on Revolut’s exposure of Bitcoin activity through a fake request examined the risk created when transaction history is tied to a real identity. A criminal who knows a customer’s name, contact details and past Bitcoin activity can write a phishing message that looks far more credible than a generic scam.
International Cyber Digest posted on X that the threat actors had begun publishing sensitive customer information and were threatening further releases. Its post included screenshots said to show customer material, but those screenshots do not independently establish their source or authenticity.
International Cyber Digest’s post was followed by a similar claim from Evan Luthra, who shared an image said to show redacted customer material and alleged that the group had demanded payment.
🚨THINGS ARE GETTING UGLY FOR REVOLUT!!!
The group targeting the company has started leaking alleged customer data tied to high-profile clients.
Now they’re demanding payment and threatening to dump more private messages, customer records and internal information.
They’re also… https://t.co/1rPcqLVb0H pic.twitter.com/xyfkedn3bg
— Evan Luthra (@EvanLuthra) September 13, 2026
The alleged releases appear designed to give the payment demand weight. By publishing material said to belong to real customers, the group can try to show that it has access to sensitive records and can cause further harm without accessing customer funds. If the material is authentic, additional publication could expose more people to fraud. Criminals may also try to use or distribute customer datasets for phishing and impersonation, although there is no verified evidence that this group has sold the Revolut data or plans to do so.
That changes what affected users should look for after the breach. Identity documents, account records and previous Bitcoin activity can be used to tailor an approach to a particular customer.
Revolut has confirmed that sensitive customer information was disclosed, while the alleged ransom and public release of records remain unverified. For users who may have been affected, the practical risk is a more targeted form of fraud: a message or call that uses genuine personal or transaction details to appear legitimate. Any unexpected request about a Revolut account or Bitcoin activity should be checked through the official app, not through a link or contact number supplied by the sender.
This article is provided for informational purposes only and does not constitute legal, financial or cybersecurity advice.
The post Revolut Hackers Reportedly Demand 10,000 BTC Ransom appeared first on Coindoo.