Home Blog Page 5

Stolen Revolut Files Surface as Attackers Press for Payment

TL;DR

  • Stolen Revolut customer data, including identity documents and verification selfies, has begun circulating online.
  • Attackers say they will release more files daily until Revolut pays, while the company has not addressed the reported ransom figure.
  • The data breach may expose Revolut customers to greater phishing risk because identity details can be linked with financial and Bitcoin transaction records.

Stolen Revolut customer data is now circulating online, and the attackers behind it say more is coming.

Identity documents and verification selfies belonging to at least two named individuals surfaced over the weekend. They belong to professional tennis player Alexander Shevchenko and Felix Römer, chief executive of the crypto gambling platform Gamdom. A monitoring account, International Cyber Digest, posted the images on X on September 13. Other media outlets corroborated a Telegram message in which the attackers said they would keep releasing files daily until Revolut paid.

A ransom figure of 10,000 Bitcoin, worth roughly $780 million at current prices, has circulated since Monday. It traces to a single X post citing the same monitoring account. Revolut has stayed silent on the figure. The attackers themselves remain anonymous, with no group, individual, or government identified as the source.

What happened

Revolut told customers on September 11 that an unauthorized party had obtained sensitive information. The party had submitted fraudulent requests from an email account on a legitimate government agency’s domain. The company complied with a request it believed to be authentic. 

Revolut confirmed the data breach to reporters the following day, describing it to TechCrunch as “a sophisticated external impersonation scam.” The company said the incident never touched its own systems or customer funds. It blocked the email address once it identified the fraud. Revolut then alerted the impersonated agency, law enforcement, data-protection authorities, and financial regulators.

Revolut did not disclose which agency was impersonated. It also remains unknown how many customers were affected and in which markets.

What was exposed

The exposed data included dates of birth, postal and email addresses, and phone numbers, along with copies of passports or driving licences. For some customers it extended further: occupation details, verification selfies, account statements, and full transaction histories.

Mark Karpelès led the collapsed Bitcoin exchange Mt. Gox before its 2014 bankruptcy. He posted a copy of the notice he received on September 11, confirming he was among the affected customers. His copy listed additional financial detail: IBANs, withdrawal records, and complete Bitcoin transaction histories.

Blockchain investigator ZachXBT separately publicized the notice on Telegram. He assessed the incident as targeted toward high-net-worth customers, an assessment Revolut has not confirmed.

Why the Bitcoin and identity combination matters

A public blockchain records transaction activity without naming the wallet’s owner. Financial companies close that gap by holding the identity behind the address. When both records land in the same hands, they sketch a fuller picture of a customer’s finances.

The leaked files tied to Römer and Shevchenko give that risk a concrete shape. Both are wealthy and publicly identifiable, matching the pattern ZachXBT described before any data had surfaced. Victims of this leak could have a harder time to spot phishing attempts because forged messages may contain details that match real transaction records.

Not Revolut’s first incident

Revolut has now disclosed two customer data breaches in four years. In September 2022, attackers used a phished employee credential to break into customer records. The exposure covered the names, addresses, phone numbers, partial card data, and transaction records of 50,150 customers. Lithuania’s State Data Protection Inspectorate, the lead supervisory authority for Revolut’s European operations, investigated that incident.

A separate episode involved no customer data at all. Organized criminal groups exploited a flaw in Revolut’s payment systems between 2021 and 2022. They tricked the company into refunding declined transactions with its own money. The Financial Times reported in 2023 that the scheme initially drained about $23 million. Revolut recovered some of that money and put its net loss at roughly $20 million.

Where it stands

This incident hits Revolut in a period of rapid growth. It now holds banking licenses in more than 30 countries and serves customers in upward of 160 countries and regions overall. The company recently expanded into India, Mexico, France, and the UAE.

Earlier this month, the U.S. Office of the Comptroller of the Currency granted the company conditional approval for a national bank. The fintech expects to launch that bank in 2027. It is separately weighing a public listing that could value it near $200 billion.

The attackers say fresh files will appear daily until Revolut meets their demand. Whoever holds the data now controls how the story develops from here.

Xinbi Faces US Sanctions as More Than $52 Million Is Restrained

TL;DR

  • US authorities restrained more than $52 million tied to Xinbi Guarantee on September 9, with the Justice Department’s Scam Center Strike Force seizing Telegram channels and two wallets while targeting 47 more.
  • Treasury sanctioned Xinbi and two supporting firms, SafeW Technology and Anwen Technology, and says the marketplace processed more than $24 billion since around 2022.
  • The Justice Department has given no timetable for victim distributions, and Xinbi has already moved funds into a stablecoin with no freeze mechanism, signaling the marketplace is adapting around the restraint.

US authorities restrained more than $52 million in cryptocurrency tied to Xinbi Guarantee on September 9, targeting a marketplace accused of laundering proceeds for scam operations worldwide. Treasury and the Justice Department carried out the coordinated action, which freezes the targeted funds while the legal process continues.

WHAT IS XINBI

Xinbi is a Chinese-language marketplace that has operated through Telegram since around 2022, drawing more than 650,000 users. Treasury said the platform connected scam-center operators with vendors selling money-laundering services, technology and other tools. Vendors advertised their services and posted their own cryptocurrency payment addresses directly in Xinbi’s Telegram channels, turning the channels themselves into a storefront.

The marketplace ran on an escrow system. Xinbi held payments until vendors completed the purchased services, giving buyers and sellers a reason to trust each other despite operating a criminal marketplace.

Treasury said Xinbi processed the equivalent of more than $24 billion in cryptocurrency and conventional currency since around 2022.

THE ENFORCEMENT ACTION

Treasury designated Xinbi as a significant transnational criminal organization, and it sanctioned two companies that supported the marketplace. SafeW Technology built a messaging app in Singapore. Anwen Technology, based in Cambodia, developed a crypto wallet known as XinbiPay or NewPay.

The Justice Department’s Scam Center Strike Force, a multi-agency unit formed this year to target scam-center infrastructure, carried out the seizure alongside Treasury. A federal court authorized the Strike Force’s seizure of Xinbi’s Telegram channels on September 7. The department announced that seizure alongside the wider financial action two days later.

The Strike Force seized two cryptocurrency wallets holding about $12 million combined. Investigators targeted 47 more wallets they believe are connected to laundering on Xinbi’s network or to vendors serving scammers. Investigators said they traced funds belonging to US victims to specific vendors that advertised money-laundering services in Xinbi’s Telegram channels. Those measures brought the total restrained to more than $52 million, the department said.

TRACING AND FREEZE DETAIL

Elliptic, a blockchain analytics firm, said it helped the US Secret Service trace the assets and put the total at $52.8 million.

The Justice Department thanked Tether for assisting the investigation. Blockchain investigators separately reported a freeze of about $39.3 million in USDT across ten addresses on Tron, a blockchain network where USDT commonly circulates.

USDT is a dollar-linked stablecoin, and its issuer can block specified addresses from moving the tokens they hold. That feature lets Tether act when law enforcement identifies wallets connected to sanctions or suspected crime.

The $39.3 million freeze likely overlaps with Elliptic’s $52.8 million figure, though the disclosures do not confirm exactly how. The two totals should not be added together, and it remains unclear which companies controlled the other wallets covered by the broader restraints.

SANCTIONS CONSEQUENCES

OFAC’s designation means any property connected to Xinbi, SafeW Technology or Anwen Technology automatically becomes blocked the moment it comes under a US person’s control — whether that’s a US bank, exchange, or individual. A category of “US persons” covers citizens, residents and US-incorporated entities. Those US persons must freeze such property and report it to OFAC, and they generally cannot transact with the three designated entities at all unless they obtain an exemption or authorization.

Moreover, the restrictions can affect companies outside the United States. A foreign platform could face exposure if it causes a US person to process a prohibited transaction.

The $52 million restrained is the visible number from Wednesday’s action. Less visible: wallet providers, exchanges and payment companies across the industry now have to screen for assets connected to Xinbi, SafeW and Anwen, and review any dealings with the network.

RESTRAINED, NOT RECOVERED

Authorities must connect the restrained assets to specific crimes and resolve competing claims before any distribution can occur. So far, the Justice Department has said neither how much could reach victims nor when a recovery process might begin.

Wednesday’s action brought the Strike Force’s cumulative total of restrained scam-related funds to about $938 million. It shows how far its campaign against scam-center infrastructure has grown since its formation this year. But Xinbi itself is already adapting. Within hours of the freeze, the marketplace moved about $2.8 million of its remaining funds into USDD, a stablecoin with no central issuer and no freeze mechanism, according to Elliptic.

Tether Puts $400 Million Behind Global Lending Fund

TL;DR

  • Tether and Fasanara Capital launched a $400 million private credit fund that will deploy capital through fintech lenders.
  • StableFund will use USDT infrastructure for cross-border settlement, currency conversion and treasury transfers.
  • The companies have not disclosed how sponsor contributions split or where the fund will deploy its capital first.

Tether and Fasanara Capital launched a $400 million private credit fund on September 9, taking the stablecoin company deeper into lending outside public markets. The partners aim to attract as much as $3 billion from institutional investors.

The fund will finance businesses and consumers through fintech lenders operating in more than 60 countries. Tether will help find opportunities linked to its USDT stablecoin and provide the payment infrastructure. Fasanara will manage the investments and decide how to deploy the capital.

Fasanara will control the lending strategy

The companies call the vehicle StableFund, an evergreen fund that can keep investing and accepting capital without a fixed closing date. London-based Fasanara will serve as the investment manager and says it manages more than $6 billion.

The manager plans to use the new fund for short-duration, asset-backed credit. These are loans designed to mature relatively quickly and supported by assets or expected payments. The underlying financing may include business loans, consumer credit, trade receivables and supply-chain finance.

Fasanara’s role also defines a key boundary around Tether’s move into private credit. Lenders negotiate these loans privately instead of selling bonds in public markets. Tether will act as a co-sponsor, originator and adviser. It will not manage the fund or make every loan directly to the final borrower.

Instead, fintech platforms in Fasanara’s network will connect the capital with businesses and consumers. The announcement says the strategy will focus partly on borrowers that conventional funding channels do not serve well.

USDT will move money through the lending network

USDT aims to track the US dollar and can move across several blockchain networks. StableFund plans to use that infrastructure for cross-border settlement, currency conversion and treasury transfers.

Tether will also provide links that allow money to move between bank currencies and stablecoins.

The companies have not explained whether borrowers will receive loans denominated in USDT or must repay in the stablecoin. USDT may instead operate mainly as the settlement rail used to transfer capital between institutions and lending platforms.

That missing detail affects how borrowers and investors understand currency and payment risk. Faster settlement can reduce delays, but it does not remove the chance that a borrower defaults or that collateral loses value.

The fund is separate from USDT’s backing reserves

Tether Holdings runs several distinct business lines beyond stablecoin issuance, including bitcoin mining under Tether Power and tokenization services under Hadron.

USDT’s reserves sit in a dedicated pool, mostly US government debt, and undergo regular independent attestation. StableFund draws on corporate capital instead, most likely retained profit or other assets outside that reserve. A default in the fund’s lending book would not, on its own, weaken USDT’s reserve position.

Tether has not disclosed which corporate funds financed its side of the $400 million commitment.

Where the money goes is still unclear

The companies have not said whether StableFund has originated its first loan, or how the $400 million splits between Tether and Fasanara.

Fasanara’s fintech network spans more than 60 countries, but the announcement says little about where the fund plans to deploy its capital first. 

India Moves to Block 15 Crypto Platforms Over AML Compliance

India Bans Offshore Crypto Exchanges
India Bans Offshore Crypto Exchanges

TL;DR

  • India ordered access restrictions against 15 crypto platforms that authorities say were serving Indian users without meeting AML registration requirements.
  • FIU-IND is seeking the removal of their apps and websites from public access, but the notices do not freeze or seize customer crypto assets.
  • It remains unclear when every restriction will take effect or how the affected platforms will handle withdrawals and account access.

India has ordered access restrictions against 15 crypto service providers after its financial intelligence agency said they were serving users in the country without meeting anti-money-laundering requirements.

The Financial Intelligence Unit-India, or FIU-IND, issued non-compliance notices on September 9 under Section 13 of the Prevention of Money Laundering Act, or PMLA. India is blocking crypto platforms through separate notices seeking the takedown of their applications and website URLs from public access.

FIU-IND names 15 crypto services

The government’s list covers trading platforms as well as services that allow users to exchange or transfer digital assets. The names include Weex, Blofin, Rezorex, Bitunix, DigiFinex, Toobit, XT.com, Latoken, WOO X, Pionex, ChangeNow, SimpleSwap, FixedFloat, WhiteBIT and Guardarian.

FIU-IND said the services were operating without complying with relevant provisions of the PMLA in India. The agency also invoked its role under India’s Information Technology Act and intermediary rules when issuing the app and URL takedown notices.

The official announcement covers the notices and takedown requests, but it does not say when any platform goes dark. Whether all 15 were blocked by September 10 is unclear.

Why offshore platforms fall under Indian AML rules

India brought virtual digital asset service providers into its AML and counter-terrorist-financing framework in March 2023. Businesses covered by the rules must register with FIU-IND as reporting entities and meet obligations that include reporting, record keeping, customer due diligence and transaction monitoring.

The framework applies according to the activities a business provides, not simply where it is incorporated or physically based. That means India is blocking crypto platforms that operate offshore when authorities determine they are serving the Indian market without fulfilling domestic compliance requirements.

The September 9 action extends a pattern that goes back nearly three years. FIU-IND issued its first show-cause notices to nine offshore exchanges in December 2023, including Binance, Kraken and KuCoin. It followed with notices to 25 more offshore platforms in October 2025, among them BingX, LBank, CoinW, CEX.IO and Poloniex. By early 2026, roughly 49 exchanges had registered with FIU-IND, 45 of them based in India and four operating offshore. The agency collected about ₹28 crore (roughly $3.4 million) in penalties during the 2024-25 financial year, including a ₹18.82 crore ($2.25 million) fine from Binance.

An access restriction is not an asset seizure

For users, blocking a service is different from freezing assets. The September 9 release calls for apps and URLs to be removed from public access.It targets the platforms, not customer accounts, and it does not state that any crypto balances have been frozen or seized.

A customer may still hold a claim to assets on a restricted platform. Logging in to trade or withdraw them is another matter, and the notice does not address it.

Platform responses will determine the next steps

None of the 15 companies has said whether it will seek registration with FIU-IND. It’s unclear whether apps already installed on users’ devices will keep working. Guidance on withdrawals or account access for Indian customers hasn’t been announced either.

There is no official figure for how many Indian customers use the 15 platforms or the value of assets they hold there. The government’s announcement addresses the companies’ compliance status, not customer exposure.

Earlier rounds of enforcement often ended with platforms registering and paying penalties. Binance and KuCoin both took that route after the 2023 notices. Whether any of the 15 named this week follow them is still open.

Ringleader Pleads Guilty in $245 Million Crypto Scam

TL;DR

  • Malone Lam pleaded guilty to a racketeering charge tied to an international network accused of stealing more than $263 million in cryptocurrency.
  • The social engineering scam relied on impersonation, stolen credentials and remote access to get around crypto wallet security.
  • Lam faces up to 20 years in prison, while seven other defendants have not yet resolved their cases.

Malone Lam pleaded guilty on September 8 to a racketeering charge tied to an international cybercrime network he organized. Prosecutors say it stole and laundered more than $245 million in cryptocurrency.

According to prosecutors, the group used social engineering to persuade crypto holders to surrender account access and sometimes they broke into homes to steal devices. The guilty plea brings a conviction for the person prosecutors identify as the operation’s organizer. The wider case is not over.

Lam admits role in racketeering conspiracy

Lam, a 22-year-old Singapore citizen and recent Miami resident, admitted to one count of participating in a racketeering conspiracy. The charge covers organized criminal activity conducted through an enterprise, commonly known as a RICO conspiracy.

The US Justice Department said the operation began no later than October 2023. It continued through at least May 2025. Lam identified targets and coordinated participants with different roles, according to prosecutors.

Participants lived in several US states and other countries. Some found potential victims, while others made fraudulent calls, accessed databases, laundered funds or carried out residential burglaries.

Lam faces a maximum prison sentence of 20 years. Judge Colleen Kollar-Kotelly set a status hearing for December 8, 2026, ahead of sentencing.

How the crypto social engineering scam worked

The group didn’t need hackers to break into wallets or exchanges. They targeted the weakest link: the person holding the keys.

For example, conspirators posed as representatives of Google and crypto exchange Gemini during one major theft. The Associated Press reported that they convinced a Washington, DC, resident to provide access credentials and security codes. The attackers then took more than 4,100 bitcoin, currently valued at roughly $245 million. A May 2025 superseding indictment put the full RICO conspiracy at more than $263 million in alleged crypto thefts, including a separate $14 million theft in July 2024.

The Record said members persuaded the victim to install remote-access software. That gave them another route into information stored on the computer.

Prosecutors describe a broader operation with multiple victims. Some members allegedly searched stolen databases for people with large crypto holdings.

The wallet was not the only security boundary

Crypto owners often focus on the private keys and seed phrases that control blockchain funds. This case shows that email, cloud storage, phone calls and devices can become part of the same security boundary.

A transaction remains valid when someone uses the correct credentials, even when a criminal obtained them through deception. Unlike a fraudulent bank transfer, a blockchain transaction cannot be reversed after the fact.

A hardware wallet can protect keys from an online attacker. It can’t protect against exposed personal data or someone getting physical access to the device. In this case, social engineering against a crypto holder was enough to bypass protections that remained technically intact.

The attackers in this case posed as Google and Gemini staff to gain the victim’s trust.

Other defendants, most cases still open

Lam is one of 18 defendants charged in the wider case and the 11th to plead guilty, according to the Associated Press.

The Justice Department has released no recovery figure for victims, and the full record of exchanges, wallets and laundering routes used by the network remains incomplete.

Seven defendants have not yet resolved their cases, keeping the broader prosecution active.

- Advertisement -

FEATURED