Revolut hit by alleged mass KYC leak as attackers publish customer IDs daily on Telegram

cyb3rops · x · 2026-09-14

According to a thread by KuptoKosmos, attackers began publishing Revolut customers' KYC files on Telegram starting September 13 — verification selfies, ID documents and more — one example per day, threatening to continue until Revolut pays and to release internal messages about how the team handles data.

The first names tied to leaked files are Gamdom founder Felix Römer (whose German ID and Revolut verification photo appeared in screenshots; he publicly replied "Ah wtf @Revolut") and ATP tennis player Alexander Shevchenko. The attackers accuse Revolut of handing over sensitive data to state requests without verifying them, including information outside its jurisdiction.

The thread's author uses the incident to argue that KYC exists to trace customers rather than protect them, and warns that exposed users — whose photos, addresses and wealth details are now in unknown hands — face real kidnapping and extortion risks. The breach has not been officially confirmed, but if accurate it would be a severe fintech data-security failure.

Related event: Revolut Confirms Data Breach as Hackers Publish Customer KYC Data Daily in Extortion Bid(5 posts)→

Original post →

More from Safety

Safety channel →