Revolut Attackers Demand Daily Ransom as Customer Data Leaks Escalate
Revolut customers are facing a heightened risk of identity theft and account takeover as attackers continue to leak sensitive customer data online. The threat actors behind the breach have stated that they will release more information daily until Revolut 'pays', according to statements on Telegram and X.
The leaked materials include facial-verification images, scanned identity documents, full names, dates of birth, occupation, contact information, account statements, complete transaction histories, and records of Bitcoin transactions. Revolut attributed the breach to a sophisticated external impersonation scam using a legitimate government-domain email address, stating that customer funds and systems were unaffected.
Revolut has confirmed that at least one user contacted by the company is among those whose details appear in the leak. The presence of transaction history and identity verification data can expose customers to additional downstream risks, such as targeted phishing, consent-manipulation scams, and attempts to correlate personal data with financial activity.