
Threat actors behind a reported Revolut customer-data leak have begun sharing stolen personal information online and say they will publish additional details each day until the company “pays,” according to statements circulated on Telegram and an X post by International Cyber Digest. The materials reportedly include facial-verification images and scanned identity documents, raising concerns about identity theft and fraud risk.
Revolut previously told customers that the exposed dataset includes full names, dates of birth, occupation, contact information, account statements, and complete transaction histories—along with records of Bitcoin transactions—following what the company described as a “sophisticated external impersonation scam.” Revolut also said its systems and customer funds were unaffected and that the breach involved a “limited number” of customers.
Key takeaways
- Attackers say they will release more Revolut customer data daily until “revolut pays,” according to Telegram messages discussed in social posts.
- Reportedly exposed items include selfies and copies of identity documents, which could materially increase identity theft and account-takeover risks.
- Revolut states the leak stems from an external impersonation scam using a legitimate government-domain email address and says customer funds and systems were unaffected.
- Customers mentioned in the leaked information include at least one Revolut user contacted by the company, based on confirmation provided to Cointelegraph.
Leak escalates with daily release threats
International Cyber Digest, in an X post shared on Sunday, said the newly leaked materials include selfies and identity documents belonging to tennis player Alexander Shevchenko and Felix Römer, CEO of online crypto casino Gamdom. The same X post points to Telegram messages in which the attackers vowed to keep releasing additional data every day until “revolut pays.”
Such “data ransom” behavior—where perpetrators threaten incremental public disclosure—can heighten pressure on affected individuals and complicate mitigation efforts, since victims may face a moving target as new documents and personal details become available.
What Revolut says was exposed
In its earlier customer communication, Revolut said the compromised information included both identity and financial records. The company reported that the leak covered personal details (including full name, date of birth, occupation, and contact information), as well as account statements and full transaction histories, including entries related to Bitcoin transactions.
Revolut attributed the incident to a “sophisticated external impersonation scam,” in which an attacker used an email address from a legitimate government agency domain to submit fraudulent requests for information. Revolut also emphasized that the breach affected a “limited number” of customers and that its systems and customer funds were not impacted.
While Revolut’s characterization centers on information-access methods rather than internal system compromise, the scale and sensitivity of the data described—particularly identity verification materials—still make the impact significant from a cybersecurity and personal-safety perspective.
Customer confirmation adds credibility to the alleged breach
Cointelegraph reported that Römer, one of the customers whose details appear in the leak, told the publication that the attacker-provided information appears to originate from Revolut. He also confirmed he was among the customers contacted by Revolut on Friday.
Römer’s confirmation matters because it connects the publicly shared documents and images to a real individual who says Revolut identified him as affected. For investors and builders in the crypto and fintech ecosystem, that linkage underscores how customer onboarding, identity verification, and account reporting workflows can become high-value targets—even when the underlying issue is attributed to impersonation rather than malware or on-chain theft.
Aside from its earlier customer statement, Revolut did not provide additional comment beyond what it told customers previously.
Why the exposed identity materials are a serious risk
According to the reporting around the leak, the disclosed package includes facial-verification images and scanned identity documents. From a threat-model standpoint, this is particularly concerning because such material can be used to:
- Support identity theft, including attempts to open or take over accounts elsewhere using stolen documentation.
- Enable fraud against services that rely on document checks or selfie-based verification.
- Increase the plausibility of social engineering by giving attackers accurate personal context.
Even if Revolut’s systems and funds were not compromised, the presence of transaction history and identity verification data can expose customers to additional downstream risks, such as targeted phishing, consent-manipulation scams, and attempts to correlate personal data with financial activity.
For crypto users in particular, leaked transaction histories can also make customers easier to profile, especially where attackers seek to identify spend patterns or platform usage. While not every threat directly targets crypto wallets, the broader ecosystem of identity and banking-style verification often intersects with crypto on-ramp and custody services.
Readers should watch closely for whether additional information is indeed released on a daily cadence, and whether Revolut updates its guidance to customers as more materials appear online. The key uncertainty remains the full scope of the leak and whether any further remediation steps—such as expanded alerts or changes to verification and data-access processes—will follow.
https://www.cryptobreaking.com/revolut-attackers-warn-of-ongoing/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Revolut%20Attackers%20Warn%20of%20Ongoing%20Daily%20Customer%20Data%20Leaks%20
Comments
Post a Comment