Revolut Confirms Data Breach as Hackers Publish Customer KYC Data Daily in Extortion Bid

Fintech company Revolut has confirmed a data breach. Reportedly, attackers exploited a legitimate government agency email domain to submit fake customer data requests, bypassing verification to extract information; the leaked data includes passports, verification selfies, account statements, and transaction records. Since September 13, hackers have been publishing customer KYC data day by day on Telegram in an extortion campaign, and the incident is still unfolding—highlighting the risk of abuse in data-request processes based on identity impersonation.

Confirmed

Unconfirmed

Why it matters

2026-09-14 ~ 2026-09-15 · 5 related posts

Primary sources

1 near-duplicate retellings: CarissaVeliz