Revolut Attackers Threaten Daily Customer Data Leaks
Attackers behind Revolut’s recent customer data breach have begun publishing stolen records online and are threatening to release more information every day unless the fintech company pays them.
The escalation follows Revolut’s confirmation on September 12 that an unauthorized party obtained sensitive customer information after using an email address from a legitimate government agency domain to submit fraudulent information requests. Revolut said its internal systems and customer funds were not compromised.
Attackers Publish Identity Documents and Verification Selfies
Posts attributed to the attackers show customer identity documents and facial verification images being released through Telegram. The group has threatened to publish additional records daily unless Revolut pays.
The newly published material reportedly includes records belonging to tennis player Alexander Shevchenko and Felix Römer, chief executive of crypto casino Gamdom. The extent of the attackers’ full dataset has not been established, and Revolut has not disclosed how many customers are affected. No verified ransom amount has been disclosed by Revolut.
Exposed Records Include Bitcoin Transaction Histories
Notices sent to affected customers said exposed records may include names, dates of birth, occupations, postal and email addresses, telephone numbers, passports, driving licenses and verification selfies.
Account statements, IBANs, withdrawal records and complete transaction histories were also potentially disclosed, including records of Bitcoin transactions. The exposed material therefore includes both identity information and detailed financial records for some affected customers.
Fake Government Requests Bypassed Revolut Controls
Revolut described the incident as an external impersonation attack rather than a breach of its core infrastructure. The unauthorized party used an email address on a legitimate government agency domain to submit fraudulent information requests that Revolut initially treated as genuine.
The company blocked the address after discovering the deception and notified the government agency, law enforcement, data protection authorities and financial regulators. Revolut has described the number of affected customers only as “limited” and has contacted them directly.
It remains unclear how the legitimate government-domain address came to be used, how much customer information the attackers obtained or how much additional material they may release. Revolut has not disclosed a payment demand amount.