Attackers claim they are publishing Revolut customer data to force a payout

Screenshots show identity documents and verification photos; Revolut says its systems and customer funds were unaffected.

By · Published

Primary source: International Cyber Digest

Why it matters

The alleged releases show the lasting risk of exposed KYC files: passports, selfies, addresses and transaction histories can support targeted impersonation and physical threats long after a breach.

Attackers claim they are publishing Revolut customer data to force a payout — Screenshots show identity documents and verification photos; Revolut says its systems and customer funds were unaffected.

A group claiming responsibility for fraudulent government information requests sent to Revolut is publishing what it says is customer identity data and threatening daily releases until the fintech pays, according to screenshots posted on X on September 13th.

The screenshots show messages attributed to the alleged extortionists alongside partially obscured identity documents and customer verification photographs. One message names Felix Romer (@Romer), the founder of crypto gambling platform Gamdom and marketplace Skins.com, and claims to contain his full know-your-customer file. The source post also said records belonging to a professional tennis player were being circulated.

The files' authenticity has not been independently established. The images nonetheless mark an escalation from the breach Revolut confirmed on September 12th: the people who obtained the records are now claiming to use public disclosure as leverage for payment.

Revolut confirmed it handed over customer records

TechCrunch reported that Revolut disclosed sensitive customer information after receiving fraudulent requests from an email account operating on a legitimate government agency domain. Revolut described the incident as a "sophisticated external impersonation scam."

According to notices sent to affected customers, the exposed material may include names, dates of birth, occupations, postal and email addresses, telephone numbers, passports, driver's licenses and facial verification images. Account statements, IBANs, withdrawal records and complete transaction histories, including Bitcoin activity, may also have been disclosed.

Revolut told The Block that a "limited" number of customers were affected, without giving a figure or identifying the government agency whose domain was used. Revolut said it blocked the address, alerted the agency, law enforcement and regulators, and contacted affected customers directly.

"Revolut systems and customer funds are unaffected," a spokesperson told TechCrunch. The customer notice did not identify passwords, card PINs or cryptocurrency private keys among the compromised records. Revolut also said biometric facial telemetry was not exposed, although verification photographs may have been included.

The distinction offers limited comfort where identity documents are involved. Passwords can be replaced. Passport copies, verification photographs, home addresses and historical financial records can remain useful for impersonation, account-recovery scams and highly tailored phishing long after the initial incident.

A trusted domain bypassed the legal-request controls

The fraudulent requests carried valid authentication because the sender operated from within the government agency's real email infrastructure, according to the customer notice. That made the messages harder to detect as forgeries, but email authentication only establishes that a message came from an authorized server. It does not prove that the person using the mailbox had the authority to request customer files.

Revolut said it later contacted the agency to verify the request and learned that the account was unauthorized. The sequence puts the focus on Revolut's process for confirming government demands before releasing customer data, particularly whether sensitive requests require verification through a second channel.

The extortion messages exploit that failure directly. Publishing selected records applies pressure to Revolut while demonstrating to other potential victims that the attackers may possess usable files. The threat to release more data each day is an attacker claim, and the screenshots do not establish the total number of records obtained.

The breach lands during a critical expansion push for the fintech founded in 2015 by Nik Storonsky and Vlad Yatsenko. Revolut says it serves more than 80 million retail customers worldwide. On September 3rd, Revolut announced conditional approval from the U.S. Office of the Comptroller of the Currency to form Revolut Bank US, with additional federal approvals still required before its planned 2027 launch.

Revolut has faced a social-engineering breach before. In September 2022, an attacker gained access to customer information in an incident that affected 50,150 people, according to a regulatory disclosure cited by TechCrunch. The latest incident used a different route: Revolut's systems were not penetrated, according to Revolut, because the records were released through a process built to answer official demands.

That route produced data with a longer and potentially more dangerous life than a conventional credential leak. The alleged extortion campaign is the first visible test of how far the attackers intend to use it.

Reader comments

Conversation for this story loads after sign-in.