Key Takeaways
- Cybercriminals have released identity verification documents and personal photos belonging to Revolut users
- Hackers are demanding ransom payment while threatening continuous daily data dumps
- The security breach stemmed from a sophisticated phishing scheme using counterfeit government correspondence
- Compromised information encompasses personal details, financial transactions, and cryptocurrency activity
- The fintech company maintains that its core infrastructure and user funds remain secure
Revolut finds itself in the midst of a major security crisis as cybercriminals have begun publishing confidential customer data online while issuing threats to continue releasing additional information daily until their ransom demands are satisfied.
The perpetrators made their intentions clear through a Telegram announcement stating: “We’re going to start releasing more and more data everyday until revolut pays for leaking their customers.”
Initial data dumps included verification documents and personal photographs connected to professional tennis athlete Alexander Shevchenko and Felix Rƶmer, who serves as chief executive of cryptocurrency gambling platform Gamdom, as detailed in an International Cyber Digest social media post.
The compromised material contains complete personal identifiers, birth dates, professional information, communication channels, banking statements, and comprehensive payment histories. Cryptocurrency transaction records, specifically Bitcoin movements, were also included.
Documentation such as passport scans and driving permits formed part of the stolen dataset, as documented by TechCrunch’s investigation.
Attack Method Revealed
The European fintech firm characterized the incident as resulting from a “sophisticated external impersonation scam.” Threat actors exploited an email address associated with an authentic governmental department domain to file falsified information access requests.
According to the company’s statement, their security team identified the unauthorized activity, promptly terminated access for the malicious address, and informed the impersonated government department alongside law enforcement authorities, privacy regulators, and financial oversight bodies.
Revolut has characterized the scope of the breach as affecting a “very limited” customer subset, with individualized notifications sent to those impacted.
The precise number of compromised accounts has not been made public by the organization.
Security Implications for Victims
Cybersecurity specialists warn that the exposure of government-issued identification and biometric verification photographs significantly elevates identity fraud risks for compromised customers.
Users whose cryptocurrency payment records have been made public may encounter heightened privacy vulnerabilities going forward.
The financial technology company has emphasized that its core platforms and customer financial assets remained untouched throughout the incident.
Operating exclusively through digital channels without traditional banking locations, the firm represents one of Europe’s leading financial technology success stories.
Management is currently orchestrating preparations for a prospective initial public offering with ambitious valuation targets reaching $200 billion.
The security incident arrives at an inopportune moment as the organization advances toward this significant corporate milestone.
Revolut has not issued any public statements regarding potential compliance with extortion demands or outlined specific countermeasures to halt subsequent data releases.
The crisis continues to develop, with threat actors maintaining their promise of persistent daily data publications until their financial requirements are fulfilled.





