Threat actors who obtained sensitive Revolut customer information have begun posting the data online and are threatening to release more every day until the company pays. The leaked material reportedly includes selfies and identity documents belonging to tennis player Alexander Shevchenko and Gamdom CEO Felix Römer. Attackers stated on Telegram that they would continue releasing data daily unless Revolut compensated them for leaking their customers' information.
Revolut confirmed that the exposed data includes full names, dates of birth, occupations, contact information, account statements, and full transaction histories, including records of Bitcoin transactions. The breach resulted from a sophisticated external impersonation scam where an attacker used a legitimate government agency email domain to submit fraudulent requests. Revolut stated the incident affected a limited number of customers and that its systems and customer funds remain unaffected.
This incident highlights the operational risks associated with social engineering attacks targeting identity verification infrastructure. By leveraging a legitimate government email domain to bypass security protocols, attackers accessed high-value personal data and cryptocurrency transaction histories. The exposure of facial verification images and identity documents significantly increases the potential for downstream identity theft, undermining user trust in digital banking compliance measures.
The attackers' demand for payment introduces a critical compliance dilemma for financial institutions. While Revolut asserts that customer funds are safe, the ongoing threat of daily data releases pressures the firm's credibility and regulatory standing. This scenario underscores the need for robust verification processes that can detect fraudulent requests even when they originate from seemingly trusted domains, as well as clear communication strategies to manage reputational risk during active extortion attempts.


