Revolut Attackers Threaten Daily Data Leaks After Customer IDs Exposed

A dark desk with scattered identity documents and a smartphone showing a facial recognition interface, illustrating a data breach.

Attackers who obtained sensitive customer information from the fintech company Revolut have begun publishing the data online and are threatening to release more each day until the company pays, according to a report by Cointelegraph. The leaked material reportedly includes identity documents and selfies belonging to Revolut customers.

The cybercriminals stated on Telegram that they would “start releasing more and more data everyday until revolut pays for leaking their customers,” Cointelegraph reported, citing an X post from International Cyber Digest on Sunday. The exposed information reportedly includes identity documents and facial-verification images of individuals such as tennis player Alexander Shevchenko and Gamdom CEO Felix Römer.

Also read: Trading Stocks Against BONER: Inside DeFi's Strangest New Market on Robinhood Chain

Key facts

  • Attackers have published identity documents and selfies of Revolut customers and threaten daily data releases until the fintech pays.
  • Revolut informed customers on Friday that leaked data includes full name, date of birth, occupation, contact information, account statements, and full transaction history, including Bitcoin records.
  • Revolut attributed the breach to a “sophisticated external impersonation scam” using a legitimate government agency email domain to submit fraudulent requests for information.
  • The company stated the breach affected a “limited number” of customers and that its systems and customer funds are unaffected.
  • The leaked data reportedly includes images belonging to tennis player Alexander Shevchenko and Gamdom CEO Felix Römer.

Context and implications

The incident highlights the growing threat of social engineering attacks, where cybercriminals manipulate trusted channels to bypass security controls. Revolut reported that the attacker used an email from a legitimate government agency domain to submit fraudulent requests for information. This method allowed the attacker to obtain sensitive customer data without directly breaching Revolut’s technical infrastructure.

Revolut has stated that the breach affected a limited number of customers and that its systems and customer funds remain unaffected. The company is continuing to investigate the incident and has engaged with affected customers.

Also read: Robinhood Crypto Volume Rose 61% in August but Remains 38% Below 2025 Levels

The risk of identity theft

The exposed identity documents and facial-verification images significantly increase the risk of identity theft for the affected individuals. Unlike a simple password leak, this data can be used to impersonate victims in financial transactions or to bypass other verification systems, creating a long-term security concern.

The threat to release data daily adds a persistent element of coercion, potentially pressuring Revolut to meet the attackers’ demands. This tactic mirrors other extortion campaigns in the cryptocurrency and fintech sectors, where attackers leverage stolen data as a bargaining chip.

Why it matters

This breach underscores the vulnerability of even well-established financial technology platforms to sophisticated impersonation scams. It affects not only the targeted customers, who face a heightened risk of identity fraud, but also the broader trust in digital finance. The incident demonstrates that robust security must extend beyond technical defenses to include vigilance against social engineering. For the cryptocurrency community, the inclusion of Bitcoin transaction history in the leaked data highlights the increasing intersection between traditional fintech and digital assets, where a single breach can expose a wide array of personal and financial information.

What to watch

Further data releases are expected daily as the attackers follow through on their threat. Additionally, Revolut’s ongoing investigation and its response to affected customers will be critical in determining the full scope of the breach and the company’s mitigation efforts.

FAQs

Q1: What data was leaked in the Revolut breach?
The leaked data reportedly includes identity documents, selfies, full names, dates of birth, occupations, contact information, account statements, and full transaction histories, including Bitcoin transactions.

Q2: How did the attackers obtain the data?
Revolut said the breach resulted from a “sophisticated external impersonation scam” where an attacker used a legitimate government agency email address to submit fraudulent requests for information.

Q3: Is my money safe with Revolut?
Revolut stated that its systems and customer funds are unaffected by the breach. However, affected customers should monitor their accounts and be vigilant against identity theft.

Jackson Miller

Written by

Jackson Miller

Jackson Miller covers Bitcoin and cryptocurrency markets for CoinPulseHQ, tracking price movements and on-chain trends.

Reported by cointelegraph.com.

Be the first to comment

Leave a Reply

Your email address will not be published.


*