The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

Who Pays 10,000 Bitcoin?

The Perimeter Desk
2026-09-15
# Who Pays 10,000 Bitcoin? The number is 10,000. Specifically, that is the amount of Bitcoin attackers are demanding from Revolut following a massive data breach. This number makes no sense, and whether you look at the 2024 lows or imagine the peaks of 2026, it's a sum that goes past corporate insurance limits and hits state budget levels. A ransom this big isn't a negotiation anymore. It's a signal. Ransomware is usually just a business deal, and you have a price, a product like a decryption key or a promise to delete files, and a way to deliver it. But when the ask is impossible, they aren't looking for a check. They're taking a victory lap or trying to pump up the value of the data so they can find other buyers on the dark web. It feels like the 2015 Ashley Madison breach. The attackers there didn't just want cash; they wanted to punish the company and make a scene; financial needs turned into moral mandates. In this case, the huge figure is just a loud marker that the system is totally compromised. The timing makes it even worse, and a hacker says the breach lasted six months before anyone noticed. For half a year, they sat in the system, moving around and stealing data slowly enough to avoid triggering alarms. Was the failure technical? I don't think so. It was procedural. Look at the Revolut mess with fake government info requests. If you can trick a fintech giant into sending over passports and selfies through an email, you don't need some fancy zero-day exploit, and you just need a believable letterhead. Revolut is the first victim. The second are the customers whose biometric data, like passport scans and selfies, are now out there in public Telegram channels, and this isn't a temporary leak. You can't rotate your face like you do a password. These people are permanently open to synthetic identity fraud; attackers can use these assets to open bank accounts or bypass KYC checks on other sites. I'm pretty sure the 10,000 Bitcoin demand is a bluff for headlines rather than real extortion. I'd change my mind if we saw evidence of a private channel where they were scaling the number down to something reachable. Right now it just looks like noise. I don't trust people rushing to blame a specific APT group based on the ransom amount alone; high demands are often false flags used to mimic loud or arrogant groups. Attribution is about probability, not headlines. The evidence is too thin for anything more than a guess. The volume of these stories is crazy. 380 reports of data breaches this week, with 67 hitting the wires today, and it's easy to get lost in it all. CISA added CVE-2026-76461 to its known exploited list on September 14, which gave federal agencies a tiny window to patch before the 17th. While we watch those patch windows and CVEs, Revolut shows that the most expensive holes aren't always in the code. Sometimes they're in the trust we put in an email that looks official. Will Revolut pay the 10,000 Bitcoin? No. The real question is how many customers already had their identities cloned while attackers spent six months unnoticed in the system.
◼

Sources

The reporting this analysis was built from. Follow the originals before acting on anything here.

  1. Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation SecurityWeek
  2. Malicious actors already using critical GitLab flaw, CISA and others warn - Cybersecurity Dive Google News Security
  3. Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution The Hacker News
  4. China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE The Hacker News
  5. Revolut Data Breach Exposes Passports, Selfies and Financial Records After Fraudsters Impersonate Government Officials - LinkedIn Google News Security
  6. Hackers demand 10,000 Bitcoin from Revolut following data breach - Computing UK Google News Security
  7. Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution SecurityWeek
  8. 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink Dark Reading

How stories are selected and rated

← More from the Desk Live Wire →

About · Methodology · Contact · Privacy

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.