Key Points
- Cybercriminals have released personal identification documents and verification photos of Revolut users
- The hackers are seeking ransom money and warning of continuous daily information releases
- The security compromise resulted from a phishing scheme using a counterfeit government agency email
- Compromised information encompasses personal details, account activity, and cryptocurrency transaction logs
- Revolut maintains that its infrastructure and user assets have not been compromised
Revolut is grappling with a significant security incident after cybercriminals started publishing confidential user data on the internet, accompanied by threats to continue releasing information daily until their ransom demands are satisfied.
The threat actors made their intentions clear on Telegram, stating: “We’re going to start releasing more and more data everyday until revolut pays for leaking their customers.”
Initial data dumps included verification documents and personal photos connected to professional tennis player Alexander Shevchenko and Felix Römer, who serves as CEO of cryptocurrency gambling platform Gamdom, as reported by International Cyber Digest on X.
The compromised materials contain complete names, birth dates, employment information, communication details, financial statements, and comprehensive payment records. Cryptocurrency transaction data, specifically Bitcoin activity, was also included.
Government-issued identification such as passport scans and driving permits were among the stolen materials, TechCrunch reported in its coverage.
Attack Method Revealed
According to Revolut’s statement, the security breach stemmed from a “sophisticated external impersonation scam.” Threat actors utilized an email account appearing to originate from an authentic government organization’s domain to file fraudulent information access requests.
The financial technology firm indicated it identified the suspicious activity, promptly disabled the compromised address, and informed the impersonated government body, law enforcement authorities, privacy regulators, and financial oversight agencies.
Revolut acknowledged the incident impacted a “very limited” subset of its user base, all of whom have received direct notification.
The precise count of affected individuals has not been made public by the company.
Potential Consequences for Victims
Cybersecurity professionals emphasize that leaked identification credentials and biometric verification photos significantly increase the likelihood of identity fraud targeting the compromised users.
Users whose cryptocurrency payment records were made public may encounter heightened privacy vulnerabilities.
Revolut emphasized that neither its technical infrastructure nor user financial holdings were breached or accessed.
The digital banking platform functions entirely online without traditional brick-and-mortar locations and ranks among Europe’s leading fintech success stories.
Revolut is presently preparing for a prospective stock market debut and seeks to achieve a market capitalization reaching $200 billion.
The security incident arrives at an inopportune moment as the organization works toward this significant corporate objective.
Revolut has not issued any public statement regarding whether it intends to meet the attackers’ financial demands or outlined specific measures to forestall additional data disclosures.
The crisis continues to unfold, with threat actors maintaining their promise of ongoing daily information releases pending payment satisfaction.


