Revolut Confirms Customer Data Leak From Government Email Scam

Wait 5 sec.

TLDRHackers claim they will leak more Revolut customer data every day until the company pays them.Leaked data reportedly includes identity documents and selfies of tennis player Alexander Shevchenko and Gamdom CEO Felix Römer.Revolut says the breach came from a scam where attackers used a fake government agency email address.Exposed data reportedly includes full names, birth dates, addresses, account statements and Bitcoin transaction history.Revolut says only a limited number of customers were affected and that funds and systems remain safe.Hackers who stole customer data from Revolut have started posting it online. They say more will be released every day until the fintech company pays them.The threat was shared in a message posted on Telegram. The attackers wrote they would keep releasing data “until revolut pays for leaking their customers.”International Cyber Digest posted about the leak on X on Sunday. The account said the data already includes identity documents and selfies. BREAKING: The threat actors who targeted Revolut with information-demand emails are now posting sensitive customer data, including that of high-profile clients such as tennis player Shevchenko and Römer, CEO of Gamdom/Skinscom.They want Revolut to pay up. They say they'll… pic.twitter.com/obuVOOABx7— International Cyber Digest (@IntCyberDigest) September 13, 2026Who Was AffectedTwo names have come up so far in reports. One is tennis player Alexander Shevchenko.The other is Felix Römer, CEO of online crypto casino Gamdom. Cointelegraph reached out to both Revolut and Römer for comment.The leaked files reportedly include copies of ID documents. They also include facial verification photos used to confirm identity during account signup.This kind of information can be used for identity theft. Selfies paired with ID scans are often used to get around security checks at other companies.Revolut told customers more details about what was taken. The company said the list includes full names and dates of birth.It also includes occupation, contact information and account statements. Full transaction history was included as well, covering Bitcoin transactions made by customers.How the Breach HappenedRevolut explained the cause of the leak to Cointelegraph on Saturday. The company called it a “sophisticated external impersonation scam.”In the scam, attackers used an email address tied to a real government agency domain. They used that email to send fraudulent requests asking for customer information.Revolut did not say which agency the email appeared to come from. The company has not shared how many fraudulent requests were approved before the scam was caught.This is not the first time Revolut has reported this kind of incident. The company previously said customer data was exposed through a fake government email.That earlier case followed a similar pattern. Attackers posed as officials to trick the company into handing over user information.Revolut has tried to limit concerns about the size of the breach. The company said only a “limited number” of customers were affected.It also said customer funds were not touched. Revolut stated its systems remain secure and are operating normally.Even so, the threat from the attackers suggests the leak is ongoing. They have said they plan to release new data daily.That means more customer names or documents could appear online in the coming days. Revolut has not confirmed how it plans to respond to the threat itself.Cointelegraph has not received a response from Revolut or Römer as of the latest update. This story may be updated as more information becomes available.The post Revolut Confirms Customer Data Leak From Government Email Scam appeared first on Blockonomi.