Loading article…
Fintech firm Revolut faces a security incident after attackers used a fake government request to access user data and demand a $780 million Bitcoin ransom.
Revolut has confirmed a data security incident in which unauthorized actors obtained access to customer information by masquerading as government officials [1]. The breach, which involved the submission of a fraudulent request to the fintech platform, has resulted in a $780 million ransom demand paid in Bitcoin [2].
| At a glance | |
|---|---|
| Incident Type | Data Breach / Ransomware |
| Ransom Demand | $780 Million |
| Asset Requested | Bitcoin |
| Status | Investigation Ongoing |
The security compromise occurred when attackers successfully bypassed internal verification protocols by submitting a fake government request [1]. By impersonating official authorities, the perpetrators tricked the company into disclosing sensitive user data [1]. Following the unauthorized access, the attackers issued a ransom demand for $780 million, specifically requesting payment in Bitcoin [2].
While the company has acknowledged the breach, the full extent of the compromised data remains under investigation. The incident highlights the growing vulnerability of financial platforms to sophisticated social engineering tactics that mimic legitimate regulatory or legal inquiries.
The scale of the $780 million demand marks a significant escalation in the financial stakes associated with corporate data breaches [2]. For Revolut, the incident raises immediate questions regarding the adequacy of its verification processes for incoming government or law enforcement requests.
The use of Bitcoin as the requested ransom currency underscores the ongoing challenge of tracking illicit funds in the digital asset ecosystem. As the firm works to secure its systems, the focus remains on identifying the scope of the exposed information and preventing further exploitation of the stolen data.
The incident serves as a stark reminder of the risks posed by social engineering in the fintech sector, where the intersection of traditional data management and digital assets creates high-value targets for attackers. Whether the firm can contain the fallout and restore user trust will depend on the transparency of its forthcoming security audit.
Coverage is mostly measured — 216 of 218 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Sep 15, 2026 · How we report
As of 14 September 2026, the Peru Ministry of Economy and Finance reported that its official X account was compromised by attackers who used the platform to promote a fraudulent token called $HYLO. The ministry confirmed the posts were unauthorized and stated that no financial losses were reported in connection with the incident.
The Revolut data disclosure, reported in September 2026, involved the release of customer full names, birth dates, occupations, postal addresses, email addresses, and telephone numbers. Additionally, the impersonator obtained copies of passports or driving licenses, verification selfies, IBANs, and complete Bitcoin transaction histories.
MetaMask utilizes AI-powered security partners like Blockaid to analyze websites, social feeds, and on-chain bytecode to identify phishing and malicious behavior in real time. The wallet also employs Added Protection, a feature that automatically reverts transactions that do not match their previews, and provides warnings for lookalike addresses and first-time recipients.
Scammers exploit government accounts because these platforms command high levels of public trust, which can be used to legitimize fraudulent schemes. By posting on official channels, perpetrators can more effectively use urgency—such as fake token launch dates—to bypass the critical thinking of potential victims.