Revolut Attackers Leak Selfies and IDs as Ransom Demand Escalates

Revolut attackers leak customer selfies and IDs while threatening daily data releases until the fintech pays, escalating identity-theft risks.
Table of Contents

TL;DR:

  • Attackers began publishing Revolut customer selfies and identity documents, threatening daily releases until the fintech pays, while exposed data may also include account statements and Bitcoin transaction histories.
  • Revolut said the breach resulted from fraudulent information requests sent through an email address tied to a legitimate government agency domain, not a compromise of its systems.
  • The leaks raise identity-theft and social-engineering risks even though Revolut says customer funds remain secure.

Revolut customers are facing an escalating data-extortion campaign after attackers began publishing identity documents and selfies allegedly obtained through fraudulent information requests. The leaked material reportedly includes facial-verification images and IDs belonging to affected customers, while the attackers threatened on Telegram to release more information every day until the fintech pays. The pressure campaign has moved beyond a private breach into public exposure of sensitive identity data. Revolut said the compromised information can also include full names, dates of birth, occupations, contact details, account statements and complete transaction histories, including records tied to Bitcoin transactions.

The attackers reportedly obtained the information through what Revolut described as a sophisticated impersonation scam. According to the company, the threat actor used an email address from a legitimate government agency domain to submit fraudulent requests for customer information. That method is particularly unsettling because the attackers appear to have exploited trust in official-looking communications rather than breaking directly into Revolut’s core systems. Revolut said only a limited number of customers were affected and stressed that its internal systems and customer funds remain secure, even as the leaked records create fresh risks beyond the platform itself.

Attackers began publishing Revolut customer selfies and identity documents

Daily Leak Threat Raises Pressure on Revolut

The latest disclosures included material linked to tennis player Alexander Shevchenko and Felix Römer, CEO of online crypto casino Gamdom. Römer said the details held by the attackers appeared to have originated from Revolut and confirmed that the company contacted him on Friday. The publication of recognizable customer identities increases the credibility and intimidation value of the attackers’ ransom campaign. It also raises risks of identity theft, social engineering and follow-on fraud because leaked verification images and account histories can provide criminals with unusually rich material for impersonating victims or crafting convincing future scams.

Revolut has not disclosed whether it intends to pay the attackers and provided no additional comment beyond its earlier statement about the impersonation scheme. The group, meanwhile, is threatening daily releases, creating an open-ended pressure mechanism designed to increase reputational and customer harm. The unresolved question is how much information the attackers possess and whether continued publication can be contained without meeting their ransom demand. While customer funds and Revolut’s systems were not compromised, the incident demonstrates how data obtained through fraudulent requests can expose customers to persistent security risks long after the original breach.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews