Revolut Attackers Begin Leaking Customer Data
Revolut said a limited number of customers were affected and that systems and customer funds remained unaffected after an impersonation scam exposed identity records.
- Attackers began posting sensitive Revolut customer information on Telegram, threatening to release more data daily until the fintech pays. The published files include identity documents and selfies belonging to customers.
- Revolut stated on Saturday that the breach resulted from a "sophisticated external impersonation scam." Attackers used an email address from a legitimate government agency domain to submit fraudulent information requests.
- Friday notifications from Revolut confirmed the exposure of full names, dates of birth, occupations, account statements, and full transaction histories, including records of Bitcoin transactions.
- While Revolut claimed the breach affected a "limited number" of customers, attackers reportedly threatened to release more data every day until the company pays. Systems and funds remain unaffected, the company said.
- International Cyber Digest reported on Sunday that identity documents and selfies belonging to Alexander Shevchenko and Gamdom CEO Felix were among the exposed files, increasing risks of identity theft.
15 Articles
15 Articles
Revolut Attackers Leak Selfies and IDs as Ransom Demand Escalates
TL;DR: Attackers began publishing Revolut customer selfies and identity documents, threatening daily releases until the fintech pays, while exposed data may also include account statements and Bitcoin transaction histories. Revolut said the breach resulted from fraudulent information requests sent through an email address tied to a legitimate government agency domain, not a compromise of its systems. The leaks raise identity-theft and social-en…
Revolut data leak sparks urgency vs security debate
Revolut’s recent data breach has led the industry to question whether pressure to respond quickly to official requests can weaken verification checks. Revolut sent sensitive customer information to an unauthorised third party, believing it was responding to a legitimate government request. The UK-based fintech received requests through a government agency email domain and treated them […]
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium















