跳到主内容
@wquguru
精选85Protos(RSS)加密货币多源精选 ×13

Revolut遭数据泄露,黑客索要1万枚比特币

What we know about the Revolut customer data leak

原文
发到 X
推荐理由

加密行业重大安全事件,涉及知名平台与高额勒索,直接影响用户对托管资产安全的评估与风控策略。

Attackers who tricked UK-based online bank Revolut into handing over sensitive customer information are currently releasing stolen details while allegedly threatening to keep leaking until the fintech coughs up over 10,000 BTC.

诱骗英国在线银行Revolut交出敏感客户信息的攻击者目前正在泄露被盗数据,并据称威胁说,除非金融科技公司提供超过10,000枚BTC的赎金,否则将继续持续泄露。

At current prices, that would put the ransom at roughly $780 million.

按当前价格计算,这笔赎金约为7.8亿美元。

Revolut hasn’t confirmed the demand or authenticated any of the material currently circulating online. Many on social media have also expressed doubt that this ransom demand is real, with Revolut investor and crypto analyst Max Karpis pointing out that such a payment would be easily traced, making it extremely difficult to cash out.

Revolut尚未确认这一要求或验证目前在网上流传的任何材料。许多社交媒体用户也怀疑这一勒索要求是否属实,Revolut投资者兼加密货币分析师Max Karpis指出,此类支付很容易被追踪,因此极难变现。

After Revolut’s data breach, the company has reportedly received ransom demands: pay up, or they'll release customer files.

在Revolut发生数据泄露后,据报道该公司收到了勒索要求:付款,否则他们将发布客户文件。

People claiming they hold the pack are posting ID copies and selfies on Telegram and saying they will drip more every day. One figure doing the rounds is…

自称持有数据包的人正在Telegram上发布身份证复印件和自拍,并表示每天都会放出更多数据。其中流传的一个名字是……

— Max Karpis (@maxkarpis) September 14, 2026

—— Max Karpis (@maxkarpis) 2026年9月14日

Read more: Trezor’s summer of hacks continues with Brevo email breach

阅读更多:Trezor的夏季黑客事件持续发酵,Brevo邮箱遭泄露

Attacker posed as government agency

攻击者伪装成政府机构

An unidentified third party targeted Revolut over the weekend, using a legitimate government agency domain to pass the bank’s security checks and request customer information.

一个身份不明的第三方在周末针对Revolut发起攻击,利用合法的政府机构域名通过银行的安全检查并请求客户信息。

Information potentially disclosed included names, dates of birth, addresses, email addresses and phone numbers, alongside copies of passports and driving licences.

可能泄露的信息包括姓名、出生日期、地址、电子邮件地址和电话号码,以及护照和驾驶执照的副本。

According to Revolut, the number of affected customers was “very limited,” but it stopped short of giving a precise figure.

据Revolut称,受影响客户的数量“非常有限”,但公司并未给出确切数字。

Customer notifications also reportedly referenced account statements, IBANs, withdrawal records and transaction histories, including BTC activity.

据报道,客户通知中还提到了账户对账单、IBAN(国际银行账户号码)、提现记录和交易历史,其中包括比特币活动记录。

According to posts on X, the attackers are seeking 10,000 BTC in exchange for not releasing additional customer data.

根据X平台上的帖子,攻击者正寻求以10,000枚BTC作为交换条件,承诺不再发布额外的客户数据。

The figure hasn’t been confirmed by Revolut and the bank has so far limited its public comments to confirming that customer data was disclosed.

该金额未经Revolut确认,且该行迄今为止仅公开确认客户数据已泄露,未作更多评论。

Nor has the bank indicated whether it intends to negotiate with the attackers or if the alleged material circulating online is genuine or represents the full dataset stolen.

银行也未表明是否打算与攻击者谈判,或网上流传的材料是否真实,以及是否代表被盗数据集的全部。

Bitcoin dropped to $0.019 on Revolut today

今日Revolut上比特币跌至0.019美元

Read more: OneKey ‘hacked’ already-patched Ledger app

阅读更多:OneKey‘黑客’已修补的Ledger应用

Former Mt. Gox CEO among victims

前Mt. Gox首席执行官也在受害者之列

It’s been reported that at least some affected customers may be high-profile or high-net-worth individuals.

据报道,至少部分受影响客户可能是高知名度或高净值人士。

Indeed, former Mt. Gox CEO Mark Karpelès has revealed that he was among those affected by the breach.

事实上,前Mt. Gox首席执行官Mark Karpelès透露,他本人也是此次泄露事件的受影响者之一。

The Block reported that Karpelès shared a copy of the notification he received from Revolut, which said account statements, IBANs, withdrawal records and full transaction histories – including BTC transactions – may have been exposed.

The Block 报道称,卡佩莱斯分享了他从 Revolut 收到的通知副本,其中称账户对账单、IBAN(国际银行账户号码)、提现记录以及完整的交易历史——包括 BTC 交易——可能已遭泄露。

On-chain investigator ZachXBT has also suggested that the attackers may have specifically targeted wealthy Revolut customers and that the attack appeared to involve a relatively small number of high-net-worth users.

链上调查员 ZachXBT 也指出,攻击者可能专门针对富裕的 Revolut 客户,且此次袭击似乎涉及相对较少的高净值用户。

Revolut says customer funds are safe

Revolut 表示客户资金安全无虞

In a statement, Revolut told Protos, “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.

Revolut 在一份声明中告诉 Protos:“Revolut 最近发现了一起复杂的冒充诈骗事件,一名未经授权的第三方利用合法政府机构域名的电子邮件提交了欺诈性的信息请求。”

“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators.

“在检测到该情况后,我们立即封锁了该地址,并通知了相关政府机构以及执法部门、数据保护机构和金融监管机构。”

“Revolut systems and customer funds are unaffected. We have contacted the limited number of impacted individuals directly to inform them and provide support.”

“Revolut 系统和客户资金未受影响。我们已直接联系受影响的少数个人,告知他们并提供支持。”

This would suggest that the incident was primarily a data-disclosure event rather than an attack in which customers’ accounts or crypto were directly targeted.

这表明该事件主要是一次数据泄露事件,而非客户的账户或加密货币直接成为目标的攻击。

Got a tip? Send us an email securely via Protos Leaks. For more informed news and investigations, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

有线索?请通过 Protos Leaks 向我们发送加密邮件。如需更多深入的消息和调查报道,请在 X、Bluesky 和 Google News 上关注我们,或订阅我们的 YouTube 频道。

The post What we know about the Revolut customer data leak appeared first on Protos.

本文《关于 Revolut 客户数据泄露事件的已知信息》首发于 Protos。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →