TL;DR:
- Attackers began publishing Revolut customer selfies and identity documents, threatening daily releases until the fintech pays, while exposed data may also include account statements and Bitcoin transaction histories.
- Revolut said the breach resulted from fraudulent information requests sent through an email address tied to a legitimate government agency domain, not a compromise of its systems.
- The leaks raise identity-theft and social-engineering risks even though Revolut says customer funds remain secure.
Revolut customers are facing an escalating data-extortion campaign after attackers began publishing identity documents and selfies allegedly obtained through fraudulent information requests. The leaked material reportedly includes facial-verification images and IDs belonging to affected customers, while the attackers threatened on Telegram to release more information every day until the fintech pays. The pressure campaign has moved beyond a private breach into public exposure of sensitive identity data. Revolut said the compromised information can also include full names, dates of birth, occupations, contact details, account statements and complete transaction histories, including records tied to Bitcoin transactions.
‼️ BREAKING: The threat actors who targeted Revolut with information-demand emails are now posting sensitive customer data, including that of high-profile clients such as tennis player Shevchenko and Römer, CEO of Gamdom/Skinscom.
They want Revolut to pay up. They say they'll… pic.twitter.com/obuVOOABx7
— International Cyber Digest (@IntCyberDigest) September 13, 2026
The attackers reportedly obtained the information through what Revolut described as a sophisticated impersonation scam. According to the company, the threat actor used an email address from a legitimate government agency domain to submit fraudulent requests for customer information. That method is particularly unsettling because the attackers appear to have exploited trust in official-looking communications rather than breaking directly into Revolut’s core systems. Revolut said only a limited number of customers were affected and stressed that its internal systems and customer funds remain secure, even as the leaked records create fresh risks beyond the platform itself.

Daily Leak Threat Raises Pressure on Revolut
The latest disclosures included material linked to tennis player Alexander Shevchenko and Felix Römer, CEO of online crypto casino Gamdom. Römer said the details held by the attackers appeared to have originated from Revolut and confirmed that the company contacted him on Friday. The publication of recognizable customer identities increases the credibility and intimidation value of the attackers’ ransom campaign. It also raises risks of identity theft, social engineering and follow-on fraud because leaked verification images and account histories can provide criminals with unusually rich material for impersonating victims or crafting convincing future scams.
Revolut has not disclosed whether it intends to pay the attackers and provided no additional comment beyond its earlier statement about the impersonation scheme. The group, meanwhile, is threatening daily releases, creating an open-ended pressure mechanism designed to increase reputational and customer harm. The unresolved question is how much information the attackers possess and whether continued publication can be contained without meeting their ransom demand. While customer funds and Revolut’s systems were not compromised, the incident demonstrates how data obtained through fraudulent requests can expose customers to persistent security risks long after the original breach.




