Revolut attackers threaten daily customer data leaks
Attackers reportedly published identity documents and selfies belonging to Revolut customers and threatened to release more data each day until the fintech pays.
Revolut, the London-based fintech and crypto platform, is facing an active extortion campaign after attackers reportedly obtained and published sensitive customer data, including identity documents and selfies. The threat actors have warned that additional batches of customer information will be released on a daily basis unless Revolut meets their financial demands. The full scope of the breach, including the number of affected customers, has not been publicly confirmed by the company at this time.
Revolut has previously dealt with security incidents, most notably a 2022 breach in which attackers accessed data belonging to approximately 50,000 customers through a social engineering attack targeting an employee. The platform serves over 45 million customers globally and holds a UK banking license, making data security a regulatory as well as reputational concern. The current campaign represents an escalation in tactics, with attackers applying continuous public pressure rather than conducting a single, contained breach.
The incident highlights growing risks facing fintech and crypto-adjacent platforms that store high volumes of sensitive Know Your Customer documentation. Regulators across Europe and the UK have increasingly scrutinized how such firms handle and protect personal data under frameworks including GDPR, where fines for breaches can reach into the tens of millions of euros.
Observers will be watching for an official statement from Revolut confirming or denying the breach, any regulatory response from UK or EU authorities, and whether the attackers follow through on their daily release threats.
Source: Cointelegraph