680 $BTC (51,900,166 USD) transferred from Coinbase Institutional to unknown wallet...
Binance Completes Integration of USDC (USDC) on Arc Network, Opens Deposits - 2026-09-16Binance has ...
Nvidia Needs To Worry About This Company, And Not AMD
U.S. Regulatory Agencies Expected to Advance Cryptocurrency Rules Amid CLARITY Act Stalemate
Bitcoin Core 32 enters final testing with faster validation, fee changes and security fixes
Pi Network (PI) Tumbles 14% Daily: Is a Recovery on the Horizon?
Kraken parent Payward has confirmed plans to bring onchain perpetual futures to U.S.
Malicious Uniswap v4 hooks are baiting DeFi traders with fake swap quotes
Bitcoin Buy Signal Emerges Ahead of Federal Reserve Rate Decision
krakenfx PARENT COMPANY Payward INTENDS TO BRING ONCHAIN PERPETUAL FUTURES TO U.S....
SKY (SKY) Price Prediction 2026, 2027 – 2030: Is SKY a Strong Long-Term DeFi Investment?
Circle launches Arc mainnet with USDC as native gas token
Trump and Melania’s coins are down over 95% from ATHs
Kraken Parent Payward Plans to Offer Onchain Perpetual Futures to U.S. Clients, Starting with...
Two crypto bills are in Congress today- One would eliminate capital gains tax on crypto...
Two crypto bills are in Congress todayOne would eliminate capital gains...
Whale Sells 866 BTC for 26,924 ETH Hours Before Bitcoin Price Tanked
A quick guide to analyzing a crypto project’s website
KuCoin Opens Direct USDC Transfers as Circle’s Arc Blockchain Goes Live
Bitcoin miners and other emerging AI infrastructure developers have disclosed 8 GW of
Shares of Coinbase and Strategy Shares Drop Following Senate Vote on Digital Asset Bill
Hyperliquid and Payward Launch HIP-3* Markets for US Traders
Bitcoin loses touch with the Dollar Index, U.S. stocks ahead of the Fed
Why Arbitrum (ARB) & Zcash (ZEC) Price Defying the Crypto Market Ahead of FOMC?
NEW: Bitcoin onchain activity is at one of its most subdued levels on record, with just 3.8 million
Bitcoin On-Chain Activity at Historic Lows, Only 3.8 Million BTC Transferred in Past 180 Days
US 20-year bond auction just had its worst showing ever
1,604 $BTC (121,894,733 USD) transferred from unknown wallet to unknown wallet...
Kalshi Seeks $750 Million Funding at $40 Billion Valuation
The Future of RWA + DeFi: What Comes After Tokenized Treasuries?
Tokenized Private Credit in DeFi: The Biggest RWA Category
CLARITY Act Fails in the US Senate: How the Crypto Community Reacted, and Whether Analysts See Signs of a Bottom?
BTC, ETH, and XRP Plunge After CLARITY Setback but All Eyes Turn on Fed Now: Market Watch
The Standard Chartered Effect: Is bank research becoming crypto’s new short-term catalyst?
CoinEx to Cease Operations After Nine Years, Withdrawals End December 22
Crypto's Biggest Senate Bet Collapses as Clarity Act Falls Short of 60 Votes
Bitcoin traders brace for Fed hike, but a surprise hold could pose bigger risk
Two Prime makes onchain finance push with $10 million-backed bitcoin yield vault
Deutsche Bank Seeks Approval for Digital Asset Custody Service
Circle Launches Arc Mainnet with Major Financial Institutions as Validators
Bitcoin ETFs shed $450 million as Clarity Act fails
Deutsche Bank close to debuting crypto custody for institutions
Arbitrum Price Prediction: Can ARB Turn Standard Chartered’s $10 Call Into a New Rally?
India Crypto News: Parliament Panel Wraps Year-Long Crypto Review, Report Due Soon
ICON (ICX) Price Prediction 2026, 2027-2030: Is ICX A Good Investment?
Stand With Crypto says senators who voted against the CLARITY Act will...
Bernstein says Clarity Act's failure shifts crypto regulation toward SEC and CFTC
Elizabeth Warren Said She Is Ready to Work on a New Crypto Law After the Failure of the CLARITY Act
Live updates: Zcash climbs 6% as majors slide ahead of Fed rate decision
New wallet bought $7.72M worth of HYPE via FalconX 2 hours ago
Circle launches Arc mainnet with BlackRock and Visa among validators, mints 10 billion ARC tokens
A newly created wallet (0xF426) bought 99,834 $HYPE($7.72M) via #FalconX 2 hours...
Kalshi Hits $40B+ Volume and 80% of US Prediction Market
Italy Investigates Government Email Breach Linked to Revolut Data Leak
PANews Sep 16: Cumberland Sold 1.5M PONS in Past 5 Hours After Accumulating 17.64M PONS Over Two Weeks
Circle debuts Arc blockchain which Jeremy Allaire calls ‘more consequential’ than USDC
Tokenized S&P 500 Index Fund Achieves $104 Million in Trading Volume on Base
Twenty One Capital Weighs STRC-Style Preferred Stock to Buy More Bitcoin
Cumberland, which has been accumulating $PONS for the past 2 weeks, is now starting to sell!Over the...
Ethiopia cuts Bitcoin miners’ power by 77% amid hydropower shortage: Report
KAIA (KAIA) Price Prediction 2026, 2027-2030: Will KAIA Price Skyrocket to $0.1?
The UK’s FCA has released guidance on the scope of the country’s future cryptoasset regime. The...
‘Government Is Not Accepting VDAs, Not Regulating Either’: India Panel Chief on Crypto
Coinbase Premium Index Hits One-Month Low Amid Declining US Bitcoin Demand
Intel's pre-market briefly dips, narrowing gains to 4.3%
Bitcoin's Coinbase premium sinks to one-month low, here’s why
Tom Lee: A Really Bullish Period for Crypto Over the Next 12 MonthsOn September 11, 2026, BitMine...
Apple vs. Microsoft: Which Stock Is the Smarter Buy Now?
Bitcoin ETF exits erase Monday’s rebound as spot selling deepens before the Fed
Researchers Uncovered Scheme Involving Fake Crypto Requests on Revolut
- Analysts uncovered how Revolut shared customer data via fake requests.
- At the center of the incident was not a hack of the banking app itself, but abuse of the channel through which financial institutions interact with government agencies.
- 680 Revolut customers may have been affected by the leak.
- According to researchers, the attackers used public crypto transactions and wallet addresses to obtain KYC data on potentially wealthy users.
Fintech company Revolut faced the fallout from a data leak affecting around 680 customers after attackers used compromised Italian government email inboxes to send fake requests to the fintech firm. This was reported by FT and International Cyber Digest.
— International Cyber Digest (@IntCyberDigest) September 14, 2026
BREAKING: We're in contact with the Revolut hacker. According to them, they didn't only take Revolut data, they've also compromised multiple Italian law enforcement departments.
They say the operation targeting Revolut ran for six months, and that they used Italian law… pic.twitter.com/ZYGWZEc0tL
Amid the publication of user data and possible ransom demands, researchers are detailing the attack mechanism, while lawyers and civil rights advocates point to a systemic problem with verifying government requests in the financial sector.
In addition, some of the claims are being spread by the alleged attackers themselves. Revolut has not confirmed all of the published figures and details.
According to early Revolut investor and independent analyst Max Karpis, the company received ransom demands, and people claiming to possess the stolen files began posting copies of customer documents and selfies on Telegram.
After Revolut’s data breach, the company has reportedly received ransom demands: pay up, or they'll release customer files.
— Max Karpis (@maxkarpis) September 14, 2026
People claiming they hold the pack are posting ID copies and selfies on Telegram and saying they will drip more every day. One figure doing the rounds is…
At the same time, Karpis stressed that Revolut has not yet confirmed the claimed amount of 10,000 BTC, and that the information should be treated with caution.
“Revolut still says “limited,” and that the app and the money were not hacked. This is extortion after a Revolut employee handed KYC to an unauthorised mailbox on a real government domain. Paying would not put the passports back,” he wrote.
Karpis also urged potentially affected users to take additional security measures: freeze credit lines where possible, set a new passcode and card transaction alerts in the app, and avoid engaging with people who already know the user’s IBAN or their previous cryptocurrency transactions.
Separately, he advised considering replacing a passport, since in some countries, after a document is compromised, the old number can be canceled and a new one issued. At the same time, the expert warned about another potential scam: offers to “delete the file” for money may be an attempt to extort funds again.
How Attackers Could Have Obtained Cryptocurrency Customer Data
According to an X user under the handle Korra, an attacker using the alias IAmNotAVillain employed a so-called spray-and-pray tactic: sending Revolut hundreds of cryptocurrency transaction IDs and deposit addresses, and asking for information about the accounts associated with them.
— Korra (@korraflow) September 15, 2026
BREAKING: Duel can report that the Revolut hacker used a "spray and pray" strategy, sending hundreds of cryptocurrency transaction IDs to Revolut and asking for the associated account details. Revolut complied.
This explains the sheer volume of data the hackers were able to… pic.twitter.com/RqGsuEIkMZ
Duel claims that such requests were sent under the cover of a forged European Investigation Order — a European investigative order. Revolut allegedly responded by providing archives containing customer data.
Researchers said they obtained and verified authentic copies of emails in .eml format. One of them contained 10 folders, each dedicated to a separate customer. According to Duel, the folders contained:
- Photos of identity documents
- Verification selfies
- Account information
- Unredacted transaction data
According to researchers, the password to the encrypted ZIP archive was sent in a separate email.
This scheme also explains why the attackers may have deliberately sought information about wealthy Revolut clients. Public blockchains make it possible to see addresses and transactions, meaning a crypto transaction could be used as a kind of search key for a request to a centralized financial institution.
Researchers claim the attacker sent Revolut hundreds of transaction hashes and deposit addresses that, in their view, were linked to high-asset clients. The company then allegedly returned information about the corresponding users.
Separate claims about 147 GB of data allegedly stolen from Italian government systems, as well as about the publication of client data, are being circulated by researchers and people who say they are in contact with the attackers.
Human rights advocate and Open Dialogue Foundation President Lyudmyla Kozlovska noted that new documents confirm that on July 24, 2026, Revolut refused to directly disclose information in response to a request covering 198 hashes. According to her, 169 of them were linked to Revolut Ltd in the United Kingdom, and another 29 — to the Swiss legal entity.
New evidence shows: (1) @Revolut did apply the one refusal ground the law gives it. (2) the attackers targeted in their malicious request high-value clients using blockchain transactions.
— Lyudmyla Kozlovska
Documents show that on 24 July 2026, on a request covering 198 hashes, Revolut refused… https://t.co/Hs4eHdvBuo(@LyudaKozlovska) September 15, 2026
Kozlovska claims the company invoked a legal ground for refusal — a jurisdictional limitation. The request concerned only accounts at Revolut Bank UAB in Lithuania, while in other cases the applicant was directed to the UK mutual legal assistance procedure.
At the same time, she emphasized that European anti-money laundering rules do not impose a separate obligation on a bank to verify the true party behind an authenticated government request.
“EU AML law imposes no verification duty on the bank and provides no meaningful mechanism to check who is really behind an authenticated state request. Refusal to answer carries fines in the millions,” Kozlovska said.
What Victims Are Advised to Do, and Why the Incident Has Broader Implications
Kozlovska urged European citizens to contact their Members of the European Parliament and demand urgent hearings on the use of mass financial data collection as a tool for attacks.
She also pointed to a potentially broader issue: a similar risk may apply to banks, crypto exchanges, and payment services in jurisdictions where FATF rules and relevant AML legislation are in force.
According to her, financial institutions are required to respond to properly оформлені government requests, while the mechanisms for verifying who is actually behind such a request may be limited.
Kozlovska noted that the issue has already been raised before the European Parliament by human rights organizations, victims, and experts, with the support of the Open Dialogue Foundation. She added that this year, in a resolution dated June 18, 2026, the European Parliament separately flagged the risk of transnational financial repression.
As of the time of writing, Revolut has not published separate recommendations on its X page regarding clients’ next steps in connection with the incident.
As a reminder, Revolut recently received conditional approval to establish a national bank in the United States.
Сообщение Researchers Uncovered Scheme Involving Fake Crypto Requests on Revolut появились сначала на INCRYPTED.
Source: Incrypted
BREAKING: We're in contact with the Revolut hacker. According to them, they didn't only take Revolut data, they've also compromised multiple Italian law enforcement departments.

(@LyudaKozlovska)