Stolen Revolut Files Surface as Attackers Press for Payment
TL;DR
- Stolen Revolut customer data, including identity documents and verification selfies, has begun circulating online.
- Attackers say they will release more files daily until Revolut pays, while the company has not addressed the reported ransom figure.
- The data breach may expose Revolut customers to greater phishing risk because identity details can be linked with financial and Bitcoin transaction records.
Stolen Revolut customer data is now circulating online, and the attackers behind it say more is coming.
Identity documents and verification selfies belonging to at least two named individuals surfaced over the weekend. They belong to professional tennis player Alexander Shevchenko and Felix Römer, chief executive of the crypto gambling platform Gamdom. A monitoring account, International Cyber Digest, posted the images on X on September 13. Other media outlets corroborated a Telegram message in which the attackers said they would keep releasing files daily until Revolut paid.
A ransom figure of 10,000 Bitcoin, worth roughly $780 million at current prices, has circulated since Monday. It traces to a single X post citing the same monitoring account. Revolut has stayed silent on the figure. The attackers themselves remain anonymous, with no group, individual, or government identified as the source.
What happened
Revolut told customers on September 11 that an unauthorized party had obtained sensitive information. The party had submitted fraudulent requests from an email account on a legitimate government agency’s domain. The company complied with a request it believed to be authentic.
Revolut confirmed the data breach to reporters the following day, describing it to TechCrunch as “a sophisticated external impersonation scam.” The company said the incident never touched its own systems or customer funds. It blocked the email address once it identified the fraud. Revolut then alerted the impersonated agency, law enforcement, data-protection authorities, and financial regulators.
Revolut did not disclose which agency was impersonated. It also remains unknown how many customers were affected and in which markets.
>>> Read more: Revolut Pound Stablecoin Trial Enters FCA Sandbox
What was exposed
The exposed data included dates of birth, postal and email addresses, and phone numbers, along with copies of passports or driving licences. For some customers it extended further: occupation details, verification selfies, account statements, and full transaction histories.
Mark Karpelès led the collapsed Bitcoin exchange Mt. Gox before its 2014 bankruptcy. He posted a copy of the notice he received on September 11, confirming he was among the affected customers. His copy listed additional financial detail: IBANs, withdrawal records, and complete Bitcoin transaction histories.
Blockchain investigator ZachXBT separately publicized the notice on Telegram. He assessed the incident as targeted toward high-net-worth customers, an assessment Revolut has not confirmed.
Why the Bitcoin and identity combination matters
A public blockchain records transaction activity without naming the wallet’s owner. Financial companies close that gap by holding the identity behind the address. When both records land in the same hands, they sketch a fuller picture of a customer’s finances.
The leaked files tied to Römer and Shevchenko give that risk a concrete shape. Both are wealthy and publicly identifiable, matching the pattern ZachXBT described before any data had surfaced. Victims of this leak could have a harder time to spot phishing attempts because forged messages may contain details that match real transaction records.
Not Revolut’s first incident
Revolut has now disclosed two customer data breaches in four years. In September 2022, attackers used a phished employee credential to break into customer records. The exposure covered the names, addresses, phone numbers, partial card data, and transaction records of 50,150 customers. Lithuania’s State Data Protection Inspectorate, the lead supervisory authority for Revolut’s European operations, investigated that incident.
A separate episode involved no customer data at all. Organized criminal groups exploited a flaw in Revolut’s payment systems between 2021 and 2022. They tricked the company into refunding declined transactions with its own money. The Financial Times reported in 2023 that the scheme initially drained about $23 million. Revolut recovered some of that money and put its net loss at roughly $20 million.
>>> Read more: Revolut’s $75B Valuation Fueled by Polygon Integration
Where it stands
This incident hits Revolut in a period of rapid growth. It now holds banking licenses in more than 30 countries and serves customers in upward of 160 countries and regions overall. The company recently expanded into India, Mexico, France, and the UAE.
Earlier this month, the U.S. Office of the Comptroller of the Currency granted the company conditional approval for a national bank. The fintech expects to launch that bank in 2027. It is separately weighing a public listing that could value it near $200 billion.
The attackers say fresh files will appear daily until Revolut meets their demand. Whoever holds the data now controls how the story develops from here.









