Revolut Ransomware Attack! Customer Passports and Selfies Begin to Be Exposed, Hackers Threaten "Daily Data Leaks"
Earlier reports by BlockBeats indicated that Revolut mistakenly provided some customer identity documents, account records, and even Bitcoin transaction records to unauthorized individuals due to a fraudulent data request that appeared to come from a legitimate government domain. The situation has now escalated: attackers claiming to possess this data have begun to publicly disclose some customer files and have made ransom demands to Revolut, threatening to release more data daily if the company refuses to pay.
UK financial media City AM reported on September 14 that an organization calling itself "Revolut Smilik" has confirmed to the media that it is demanding payment from Revolut and has threatened via Telegram to release "more and more data every day." The report noted that some well-known individuals' information has already been made public. Revolut has declined to disclose the number of affected individuals and has not commented on whether it will respond to the ransom demands.
This means that what was originally a data breach incident has now entered a more complicated "double extortion" phase.
Passports, Selfies, and Transaction Records May Become Ransom Chips
Revolut has confirmed that the incident originated from a "complex external impersonation scam." Unauthorized individuals sent data requests using an email account located within a legitimate government domain, leading Revolut to believe the requests were from a legitimate government entity and to provide customer data.
Reuters quoted Revolut as saying that the incident only affects a "very limited" number of customers, and that the company's systems and customer funds have not been compromised. After discovering the issue, Revolut has blocked the relevant addresses and reported it to government agencies, law enforcement, data protection, and financial regulatory authorities.
However, customer notifications indicate that the sensitivity of the disclosed data is far greater than typical names or email addresses, including birth dates, addresses, phone numbers, copies of passports or driver's licenses, identity verification selfies, as well as account statements, IBANs, withdrawal records, and complete transaction histories, which may even include Bitcoin transaction records.
The latest leaked data also shows that attackers have begun to publicly disclose identity documents and verification photos allegedly belonging to the victimized customers. Since September 13, data has been circulating on X and Telegram, including files allegedly related to some public figures.
The UK's Information Commissioner's Office (ICO) has confirmed to City AM that it has received an incident report submitted by Revolut and is currently assessing the relevant data.
This is crucial because the incident is not a traditional hacking scenario where hackers directly breach a database, but rather attackers successfully passed the company's internal verification process by utilizing "legitimate government email infrastructure." Revolut is currently facing not only email security issues but also whether financial institutions have sufficient second-layer verification mechanisms when handling law enforcement and government data requests.
Revolut emphasized that its core infrastructure, databases, and customer accounts have not been breached; however, this highlights another risk that financial institutions are increasingly struggling to prevent: even if the bank itself has not been "hacked," criminals can still obtain highly sensitive KYC and financial data if they control or misuse trusted government communication channels.
Bitcoin Transaction History Leaked, Risks Extend Beyond Identity Theft
This incident is particularly sensitive for cryptocurrency users.
Traditional identity data breaches usually lead to phishing, SIM swapping, account takeover, or identity theft risks; however, if attackers simultaneously possess real names, addresses, passports, and complete Bitcoin transaction histories, they could potentially link physical identities directly to specific cryptocurrency asset activities.
On-chain investigator ZachXBT previously suspected that the incident might involve targeted attacks on high-net-worth users. However, Revolut has yet to disclose the number of affected users or confirm whether the incident is concentrated among high-net-worth clients.
Therefore, it cannot yet be directly defined as an "attack targeting crypto millionaires," but once KYC data, addresses, and on-chain activities fall into the hands of criminals, the subsequent risks are clearly much higher than a typical email address leak.
As of the evening of September 14, Revolut has not publicly disclosed the exact number of affected customers, the names of the compromised government agencies, nor confirmed the specific ransom amount demanded by the attackers.
What can be confirmed is that the incident has escalated from "misdelivery of customer data" to public extortion; the attackers have indeed begun to release the customer data they claim to have obtained. As for their claim that they will continue to leak data "daily," this remains a threat from the attackers, and it is still necessary to observe whether subsequent data continues to appear.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Bitcoin faces an October 18 test as Trump prepares new Russia tariffs

Bitcoin Market Behavior Shifts to Buying the Dips

Grayscale: Bitcoin Could Withstand New Rate Hikes from the FED

Turkey: Financial Crisis Drives Demand for Bitcoin and Gold

Michael Saylor Refutes Bitcoin Doubts, Calls It a Successful Project

Glassnode: No Signs of Overheating in the Altcoin Market

Lemon exits Brazil over crypto licensing costs

Crypto: The 2026 Ranking of the 36 Most Favorable Countries for Adoption

Fidelity's Global Macro Director Says Bitcoin's Four-Year Cycle Bull Market May Have Started

Carl Moon Emphasizes WEEX AI Enhancing Trading Efficiency

BlackRock Transfers 54,096 ETH and 2,015 BTC to Coinbase Prime

El Niño Dries Up Dams, Ethiopia Rationing Bitcoin Miners

大冰要抄底(专注交易) Predicts Bitcoin Will Face a Major Drop

Best Crypto Exchange in Italy in 2026: What to Choose for Systematic Trading

USDT in Wallets May Be Blocked. What to Do and How to Store Them in Russia

Crypto vs Cash: 3 Clandestine Trading Posts Raided in London

Bitcoin Spot ETF Sees Net Inflow of $433 Million Yesterday, Fidelity's FBTC Leads with $311 Million

Bank of England to unwind £368 billion in gilts by September 2034

Bitcoin rises after BOJ's 1.25% rate hike, yen-carry test begins next week

Bitcoin Will Hit $1 Million, Says Kevin O’Leary—But There’s a Quantum Catch

3-year-old bug triggers $1.3 million drain and forces 10-day blockchain halt

Moscow Exchange to Trade Bitcoin, Ether, Solana, XRP, and Tron Futures Starting September 2026

Bitwise Evaluates Clarity Act's Failure as a Speed Bump

Bitcoin Could Surpass Gold, 73% of Investors Choose BTC

Bitcoin Community Acknowledges Quantum Computing Risk, Says VanEck

Haruko Faces Cyber Attack, 15 Clients Affected, Some Funds Stolen

Discussion on Bitcoin Growth and Exchange Selection at RBC Crypto Forum

Bitcoin Miners' Activity Increases, Hashrate Rises

Four Central Banks in Eight Days: Bitcoin Stays Strong









