Doctorcrypto About RSS Subscribe
Doctorcrypto
HomeBusiness › Revolut attackers threaten daily customer data leaks
Business

Revolut attackers threaten daily customer data leaks

By Diego Whitfield · · 2 min read

Attackers claiming to have breached the fintech giant Revolut have reportedly begun publishing sensitive customer information online, including identity documents and selfies, and are threatening to leak fresh batches of data every day until the company meets their demands.

What the Attackers Are Claiming

The group behind the incident says it has obtained a trove of personal information belonging to Revolut users and has already made samples public to prove its access. Among the exposed material are government-issued identity documents and verification selfies — the type of information customers typically submit during know-your-customer checks when opening an account.

According to reports, the attackers are pressuring Revolut by promising to release additional records on a rolling basis. The escalating drip-feed tactic is designed to increase reputational damage and force a faster response, a strategy increasingly common among extortion-focused cybercriminals.

Pay up, or watch your customers' private data spill out one day at a time.

Why This Matters for Fintech Users

Identity documents and biometric selfies are among the most damaging pieces of information to lose in a breach, because they can be reused to bypass verification systems and facilitate fraud far beyond a single platform. Unlike a password, a passport photo or a face scan cannot simply be reset.

The threat highlights the growing risk facing digital finance platforms, which store large volumes of highly sensitive onboarding data. Attackers have shifted from simply stealing funds to weaponizing personal records for extortion, betting that companies will pay to avoid the fallout of a public leak.

  • Exposed data reportedly includes ID documents and verification selfies
  • Attackers threaten daily releases until demands are met
  • Leaked biometric and identity data cannot be easily replaced

For affected users, the practical steps are limited but important: remain alert to phishing attempts, monitor accounts for unusual activity, and be cautious of anyone attempting to use leaked documents to impersonate them. As financial platforms continue to attract sophisticated attackers, incidents like this underscore the high stakes of storing identity data at scale.

Was this useful?👍 Yes👎 No