A well-known digital bank is now the target of one of the largest ransom demands ever made in cryptocurrency, after criminals tricked it into handing over sensitive customer records. The attackers say they will keep leaking that data publicly, piece by piece, until they are paid.

Revolut, a UK-based financial technology company offering banking, card and cryptocurrency services to more than 80 million customers worldwide, confirmed on September 12, 2026 that it disclosed sensitive customer information to criminals who impersonated a government agency.
Revolut said an unauthorized party used an email account on a real government agency’s domain to submit a fraudulent request for customer records. Believing the request was genuine, Revolut released the data before discovering it had been deceived. The company said its core banking systems, databases and customer funds were not breached, and described the incident as a “sophisticated external impersonation scam.” It has confirmed only that a “very limited” number of customers were affected, without giving an exact figure.
The exposed information reportedly included customers’ names, dates of birth, home and email addresses, phone numbers, copies of passports and driver’s licenses, verification selfies, account statements and full transaction histories, including records of Bitcoin activity. Bitcoin is a cryptocurrency — a form of digital money that operates without a bank in the middle, and Revolut is one of many mainstream financial apps that lets customers buy, hold and transfer it.
A hacking group calling itself “Revolut Smilik” has since claimed responsibility and told the outlet City AM directly that it is seeking payment from Revolut. According to multiple reports, the group has demanded 10,000 Bitcoin, worth roughly $780 million at current prices, and has begun publishing customer files on the messaging platform Telegram. It warned it would release “more and more data every day” until Revolut pays. Individuals whose information has reportedly already been posted include Mark Karpelès, the former head of the collapsed cryptocurrency exchange Mt. Gox, along with a professional tennis player and the founder of a crypto gambling platform.
Revolut has declined to confirm or comment on the ransom demand. The UK’s Information Commissioner’s Office said it has received a report and is assessing it. Financial institutions are generally required by law to comply with genuine requests from law enforcement or government agencies, which is part of why this scam was able to work. The fraudulent request looked, on paper, like a routine legal obligation.
This kind of extortion demand, made directly against a company rather than its individual customers, is however not typical. Most cryptocurrency ransom cases involve gangs encrypting a victim’s files (ransomware) or threatening to leak stolen data unless paid, and Bitcoin is the currency criminals usually request because it is harder to trace and reverse than a bank transfer.
Cases like this show why an official-looking request should never be trusted at face value. The U.S. Federal Trade Commission recommends verifying any request from a supposed government agency independently, through a phone number or website found separately rather than one provided in the message itself, and treating any demand for payment in cryptocurrency as a red flag.

