EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Revolut hackers warn of continued daily leaks of customer data

2026-09-15 08:10:52
Bookmark

Revolut data breach: Attackers threaten to disclose more customer information every day

According to statements circulated on Telegram and International Cyber Digest posts posted on the X platform, the hacker group suspected of causing the breach of Revolut customer data has begun to share stolen personal information online. They said more details would be released every day unless the company "paid".

The leaked material reportedly included facial verification images and scanned identification documents, raising concerns about the risks of identity theft and fraud. Previously, Revolut had told customers that the affected databases contained full names, dates of birth, occupations, contact information, account statements and complete transaction records-including Bitcoin transactions. The company described it as a "complex external impersonation fraud" incident. Revolut also stressed that its systems and customer funds were not affected and that the breach only involved a "limited number" of customers.

Key Points

  • Ransomware disclosure threat: According to Telegram messages discussed in social media posts, attackers claim they will release more customer data every day as long as "Revolut does not pay."
  • High-risk data exposure: The leaked items reportedly included selfie photos and copies of identification documents, which could materially increase the risk of identity theft and account takeovers.
  • Company response: Revolut pointed out that the leak originated from an external impersonation fraud using a legitimate government domain name email address and confirmed that customer funds and systems had not been affected.
  • Victim confirmation: At least one Revolut user mentioned when accepting Cointelegraph confirmation that he had been contacted by the company to confirm the authenticity of the leaked information.

The scale of leaks escalates with daily threats released

The International Cyber Digest said in an X-post posted on Sunday that the newly leaked material included selfies and identity documents of tennis player Alexander Shevchenko and Felix Römer, CEO of online cryptocurrency casino Gamdom. The same post pointed to a message on Telegram in which the attacker vowed to continue publishing additional data every day until "Revolut payments."

This kind of "data extortion" behavior-in which perpetrators threaten to gradually disclose public-puts more pressure on affected individuals and complicates mitigation efforts, as victims face a changing goal as new documents and personal details become available.

What Revolut alleges leaked

In its early customer communications, Revolut stated that compromised information included identity records and financial records. The company reported that the leak covered personal details, including full name, date of birth, occupation and contact information, as well as account statements and complete transaction history, including entries related to Bitcoin transactions.

Revolut attributed the incident to a "complex external impersonation fraud" in which attackers used email addresses from legitimate government agency domain names to submit false information requests. Revolut also stressed that the breach affected a "limited number" of customers and that their systems and customer funds were not impacted.

Although Revolut's description focuses on information access methods rather than internal systems being compromised, the size and sensitivity of the data described-especially authentication material-still has significant implications from a cybersecurity and personal security perspective.

Customer confirmation adds credibility to the allegations

Cointelegraph reported that Römer was one of the customers who appeared in the leaked information, telling the publication that the information provided by the attacker appeared to have originated from Revolut. He also confirmed that he was one of the customers contacted by Revolut on Friday.

Romer's confirmation is crucial because it connects publicly shared documents and images to a real individual who claims Revolut has listed him as an affected person. For investors and builders in crypto and fintech, this connection highlights how customer onboarding, authentication and account reporting workflows can become high-value targets-even if the root cause is blamed on impersonation rather than malware or on-chain theft.

In addition to previous customer statements, Revolut did not provide any other comments beyond those previously notified to customers.

Why exposed identity materials pose a serious risk

According to reports surrounding the leak, the disclosed data packages included facial verification images and scanned identification documents. This is particularly worrying from a threat model perspective, as such materials can be used to:

  • Support identity theft: Including attempts to open or take over accounts elsewhere using stolen documents.
  • Fraud enforcement: Fraud that relies on document inspection or selfie-based verification services.
  • Increase the possibility of social engineering: Make attacks more persuasive by providing accurate personal background.

Even if Revolut's systems and secure funds are not compromised, the existence of transaction history and authentication data may expose customers to additional downstream risks, such as targeted phishing, consent manipulation scams, and attempts to associate personal data with financial activity.

For cryptocurrency users, leaked transaction histories may also make customers more likely to be portrayed, especially when attackers try to identify spending patterns or platform usage. While not all threats are directly targeted at cryptocurrency wallets, the broader identity and bank-like verification ecosystem often intersects cryptocurrency portals and custody services.

Readers should pay close attention to whether additional information is actually released with a daily frequency and whether Revolut updates its safety guidelines for customers as more material appears online. The key uncertainties currently lie in the full scope of the breach and whether further remedial measures will be taken, such as expanding alerts or changing verification and data access processes.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP