Revolut Confirms Data Breach as Hackers Publish Customer KYC Data Daily in Extortion Bid
Fintech company Revolut has confirmed a data breach. Reportedly, attackers exploited a legitimate government agency email domain to submit fake customer data requests, bypassing verification to extract information; the leaked data includes passports, verification selfies, account statements, and transaction records. Since September 13, hackers have been publishing customer KYC data day by day on Telegram in an extortion campaign, and the incident is still unfolding—highlighting the risk of abuse in data-request processes based on identity impersonation.
Confirmed
- Revolut has confirmed the data breach, saying scammers used a legitimate government agency email domain to submit fake customer data requests, bypassing verification to obtain information.
- The leaked data reportedly includes passports, verification selfies, account statements, and transaction records.
- According to French netizen KuptoKosmos, since September 13 a group of attackers has been publishing KYC data of Revolut customers one by one on Telegram, claiming they will keep releasing it daily as long as Revolut doesn't pay, and will also dump internal data.
- Victims already exposed include high-profile customers such as tennis player Shevchenko and Römer, CEO of Gamdom/Skinscom.
Unconfirmed
- Security outlet International Cyber Digest says it is in contact with the hackers who attacked Revolut; the hackers claim the attack lasted six months and was larger in scale than publicly known—claims that have not been independently verified.
- The hackers also claim to have breached multiple Italian law enforcement systems, holding 147GB of internal data used to send data requests to Revolut; this claim likewise rests solely on the hackers' word.
Why it matters
- The attack path points to a process flaw—"initiating data requests by impersonating legitimate government email domains"—meaning any company relying on similar identity-verification mechanisms could face the same risk.
- The extortion tactic of leaking KYC data daily causes direct and ongoing privacy harm to victims, has already affected prominent customers, and could escalate further as ransom negotiations stall.
2026-09-14 ~ 2026-09-15 · 5 related posts
Primary sources
- Hackers leak Revolut customer data, name high-profile clients, demand ransom — RSync25 · 2026-09-14
- Revolut hit by alleged mass KYC leak as attackers publish customer IDs daily on Telegram — cyb3rops · 2026-09-14
- [source] Revolut Confirms Data Breach After Fraudsters Fake Government Data Requests — TechNadu · 2026-09-14
- Revolut hackers claim they also breached Italian law enforcement, holding 147GB of data — jedisct1 · 2026-09-15
1 near-duplicate retellings: CarissaVeliz