Revolut attackers threaten daily customer data leaks
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Threat actors who accessed sensitive customer data from Revolut have begun publicly posting this information and are threatening daily leaks until Revolut pays them. The leaked data reportedly includes selfies, identity documents, and detailed customer information such as names, birthdates, occupation, contact information, account statements, and Bitcoin transaction histories. The attackers claimed the data release will continue unless compensated, while Revolut confirmed the breach was due to an impersonation scam involving a legitimate government agency's email domain.
Why it matters
The leak exposes customers to increased risk of identity theft due to the release of identity documents and facial verification images. This incident also highlights potential vulnerabilities in Revolut’s data security processes and may impact customer trust and regulatory scrutiny. The source does not explicitly discuss broader industry or market impacts.
Key context
Revolut said the data breach arose from a “sophisticated external impersonation scam” where an attacker used a government domain email to fraudulently request information. The breach affected a “limited number” of customers, and Revolut's systems and customer funds remain unaffected. Previous related incidents involved exposure of customer data through fake government emails.
Key numbers and entities
Revolut (financial technology firm), Alexander Shevchenko (tennis player), Felix Römer (CEO of online crypto casino Gamdom), and Gamdom (crypto online casino) are named entities involved. Specific figures on the number of affected customers are not provided.
What remains unclear
The source does not specify how many customers were affected, the nature or size of the ransom demand, or what steps Revolut is taking to prevent future breaches. Details about the attackers’ identities and whether law enforcement is involved are also not provided.