
Revolut says customer data leak is now tied to extortion threats of daily dumps
The exposed dataset includes KYC images and full transaction histories with Bitcoin records, while Revolut says funds and systems are unaffected.
Attackers who obtained Revolut customer information have begun leaking data online and are threatening to publish more every day unless the fintech pays. Revolut says the exposure stemmed from a government-domain impersonation scam and affected only a limited number of customers.
Key Takeaways
- Threat actors have begun posting Revolut customer data online and threatened to release more “everyday until revolut pays.”
- The leaked materials were described as including selfies and copies of identity documents, raising the odds of identity theft and follow-on fraud.
- Revolut told customers the exposed dataset includes account statements and full transaction history, including records of Bitcoin transactions.
- Revolut attributed the incident to a “sophisticated external impersonation scam” and said systems and customer funds are unaffected, with impact limited to a “limited number” of customers.
Revolut Leak Turns Into an Extortion Clock as Attackers Threaten Daily Releases
Revolut’s customer-data incident is no longer being framed as a one-time exposure. It is now being presented as an extortion timeline, with attackers allegedly starting to publish customer materials and promising daily releases until they are paid.
The threat language is explicit. The attackers’ Telegram message was quoted as: “We’re going to start releasing more and more data everyday until revolut pays for leaking their customers,” positioning the campaign as retaliation and a payment demand rather than a simple data sale.
A separate social-media post on X from International Cyber Digest described the newly leaked materials as including identity documents and selfies tied to tennis player Alexander Shevchenko and Gamdom CEO Felix Römer. Those specific victim references are not independently verified in the packet, and the total volume of data already posted is not quantified.
What the Exposed Dataset Contains: KYC Images and Full Transaction Histories With Bitcoin Records
Revolut told customers the exposed dataset includes full name, date of birth, occupation, contact information, account statements, and full transaction history, including records of Bitcoin transactions.
That mix matters because it links identity to behavior. Full transaction histories can be used to profile income patterns, counterparties, and spending rails. Add Bitcoin transaction records and the targeting surface expands, because past crypto activity becomes a filter for selecting higher-value victims.
The KYC component is the sharper edge. KYC is the identity-check process that collects documents and selfies to verify a user. Facial-verification images are selfie-style photos used to confirm a person matches their identity document during onboarding. If those artifacts are in the leak, they can be repurposed for account takeovers and social-engineering attempts across other fintechs and exchanges that rely on similar verification flows.
For traders, the practical risk is not just embarrassment or doxxing. It is operational disruption. A leaked identity bundle plus contact details is enough to power convincing phishing, SIM-swap attempts, and “support desk” impersonation, especially when the attacker can cite real account-statement details to establish credibility.
Revolut’s Account: Government-Domain Impersonation Requests, Limited Scope, No Funds Impact
Revolut’s explanation points away from a direct platform intrusion and toward a process failure around inbound information requests. The company said the customer data was leaked due to a “sophisticated external impersonation scam” in which an attacker used an email address from a legitimate government agency domain to submit fraudulent requests for information.
That distinction matters for repeatability. An impersonation scam is a fraud where an attacker pretends to be a trusted entity to obtain information. If the mechanism is request-handling and verification rather than a compromised internal system, similar attempts can be replayed against other firms that process high-trust requests at speed.
Revolut also said the breach affected a “limited number” of customers and that its systems and customer funds are unaffected. What remains unresolved is the size of that “limited” cohort and whether the exposed fields match exactly what was requested via impersonation, what was delivered, and what is now being posted publicly.
The packet contains no ransom amount, no confirmed identity for the attackers, and no authoritative inventory of what has already been leaked versus what is being held back for the daily-release threat.
Signals That Confirm Escalation—or Containment—Over the Next 72 Hours
The first signal is mechanical: whether additional daily dumps appear publicly after the attackers’ stated plan to release more data every day until paid. If the cadence materializes, the incident shifts from a contained disclosure into rolling headline risk where new high-signal files can surface without warning.
The second signal is disclosure quality. Any updated Revolut communication that quantifies the “limited number” of impacted customers, or clarifies which fields were actually exfiltrated versus merely requested via impersonation, will change how counterparties price the risk. “Limited” without a number is not a risk boundary.
The third signal is validation from named alleged victims referenced in the social-media post, including Alexander Shevchenko and Gamdom CEO Felix Römer. Confirmation or denial would not settle the full scope, but it would help establish whether the leaked materials are authentic and whether the campaign is targeting identifiable, high-profile accounts.
The fourth signal is whether Revolut revises its stance on impact. A change in language around systems access or customer-funds exposure would be the line traders cannot ignore, even if the initial statement holds that funds are unaffected.
Why Traders Should Treat KYC-and-Transaction Leaks as an Operational Risk, Not Just a Privacy Story
The threshold that matters is not whether funds moved on Revolut. Revolut already says systems and customer funds are unaffected. The real test is whether the attackers can keep producing verified identity bundles and transaction histories on a schedule.
If daily releases occur and include selfies, identity documents, and full histories with Bitcoin records, the second-order damage becomes the trade. Account recovery friction, forced security resets, and targeted social engineering spill over to other venues where the same identity is reused. That is when a “limited number” breach stops being a customer-service problem and starts becoming an operational risk across a trader’s entire stack.