Revolut Ransomware Attack! Customer Passports and Selfies Begin to Be Exposed, Hackers Threaten "Daily Data Leaks"
Earlier reports by BlockBeats indicated that Revolut mistakenly provided some customer identity documents, account records, and even Bitcoin transaction records to unauthorized individuals due to a fraudulent data request that appeared to come from a legitimate government domain. The situation has now escalated: attackers claiming to possess this data have begun to publicly disclose some customer files and have made ransom demands to Revolut, threatening to release more data daily if the company refuses to pay.
UK financial media City AM reported on September 14 that an organization calling itself "Revolut Smilik" has confirmed to the media that it is demanding payment from Revolut and has threatened via Telegram to release "more and more data every day." The report noted that some well-known individuals' information has already been made public. Revolut has declined to disclose the number of affected individuals and has not commented on whether it will respond to the ransom demands.
This means that what was originally a data breach incident has now entered a more complicated "double extortion" phase.
Passports, Selfies, and Transaction Records May Become Ransom Chips
Revolut has confirmed that the incident originated from a "complex external impersonation scam." Unauthorized individuals sent data requests using an email account located within a legitimate government domain, leading Revolut to believe the requests were from a legitimate government entity and to provide customer data.
Reuters quoted Revolut as saying that the incident only affects a "very limited" number of customers, and that the company's systems and customer funds have not been compromised. After discovering the issue, Revolut has blocked the relevant addresses and reported it to government agencies, law enforcement, data protection, and financial regulatory authorities.
However, customer notifications indicate that the sensitivity of the disclosed data is far greater than typical names or email addresses, including birth dates, addresses, phone numbers, copies of passports or driver's licenses, identity verification selfies, as well as account statements, IBANs, withdrawal records, and complete transaction histories, which may even include Bitcoin transaction records.
The latest leaked data also shows that attackers have begun to publicly disclose identity documents and verification photos allegedly belonging to the victimized customers. Since September 13, data has been circulating on X and Telegram, including files allegedly related to some public figures.
The UK's Information Commissioner's Office (ICO) has confirmed to City AM that it has received an incident report submitted by Revolut and is currently assessing the relevant data.
This is crucial because the incident is not a traditional hacking scenario where hackers directly breach a database, but rather attackers successfully passed the company's internal verification process by utilizing "legitimate government email infrastructure." Revolut is currently facing not only email security issues but also whether financial institutions have sufficient second-layer verification mechanisms when handling law enforcement and government data requests.
Revolut emphasized that its core infrastructure, databases, and customer accounts have not been breached; however, this highlights another risk that financial institutions are increasingly struggling to prevent: even if the bank itself has not been "hacked," criminals can still obtain highly sensitive KYC and financial data if they control or misuse trusted government communication channels.
Bitcoin Transaction History Leaked, Risks Extend Beyond Identity Theft
This incident is particularly sensitive for cryptocurrency users.
Traditional identity data breaches usually lead to phishing, SIM swapping, account takeover, or identity theft risks; however, if attackers simultaneously possess real names, addresses, passports, and complete Bitcoin transaction histories, they could potentially link physical identities directly to specific cryptocurrency asset activities.
On-chain investigator ZachXBT previously suspected that the incident might involve targeted attacks on high-net-worth users. However, Revolut has yet to disclose the number of affected users or confirm whether the incident is concentrated among high-net-worth clients.
Therefore, it cannot yet be directly defined as an "attack targeting crypto millionaires," but once KYC data, addresses, and on-chain activities fall into the hands of criminals, the subsequent risks are clearly much higher than a typical email address leak.
As of the evening of September 14, Revolut has not publicly disclosed the exact number of affected customers, the names of the compromised government agencies, nor confirmed the specific ransom amount demanded by the attackers.
What can be confirmed is that the incident has escalated from "misdelivery of customer data" to public extortion; the attackers have indeed begun to release the customer data they claim to have obtained. As for their claim that they will continue to leak data "daily," this remains a threat from the attackers, and it is still necessary to observe whether subsequent data continues to appear.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Sam Price Emphasizes the Importance of Analyzing Bitcoin ETF Flow Trends

BitcoinHabebe Shares PTB Trading Strategy and Returns

REX Launches 2x Leveraged ETF for Strive

France crypto home attack steals €40,000: Report

DCENT Issues Urgent Security Warning for XRP Users

T. Rowe Price's Blue Macellari Discusses Bitcoin's Role in Debasement

大冰要抄底(专注交易) Shares Bitcoin Volatility Strategy

Toyosa adds BTC alongside USDT for Toyota purchases

Strategy CEO Phong Le Aims to Be JPMorgan of Bitcoin

Bitcoin: VanEck Criticizes Metaplanet's Compensation Model

Bill Miller IV Bullish on Bitcoin Amid Worsening Fiscal Situation

Bitcoin OTC Address Reserves Drop to Historic Low, Down Over 75% from 2021 Peak

Strategy Halts Bitcoin Purchases, Michael Saylor Focuses on STRC

Hut8 Bitcoin Mining Founder Marc van der Chijs: AI May Cause Systemic Shock, Reconfigure Back to BTC

Why real-time election odds are misleading prediction market crypto traders

Bitcoin's 17th Year Rekindles Old Technology Debates

Kevin O'Leary, the 'Shark' of Canadian Business, Names the Main Threat to Bitcoin on Its Path to $1 Million

Bitcoin one-year HODL wave rises to 63.3%, but signals limited demand

Poverty in the World and Crypto Adoption: What If We Crossed the Two?

Who Benefits from Interest Rate Hikes? Clarity Act's Failure Due to Established Interests

Peter Schiff Points Out SEC's Tokenized Stock Announcement is Bearish for Bitcoin

Robert Kiyosaki: The Biggest Crash in History Has Begun

What is PCE and Why September 30 is Important for Cryptocurrencies

Cryptocurrency Bill Fails, Fed Raises Rates, Yet Bitcoin Rises?

Two dormant wallets transfer 200 BTC after over 13 years

2026: The Year of Polarization in Virtual Assets

Bitcoin: JPMorgan Sees BTC Outperforming Gold

Cathie Wood Claims Bitcoin Still Has Many Opportunities

Sam Price points out BTC rises 42% in three months







