A threat actor claiming to hold sensitive customer files taken from digital bank Revolut has begun publishing identity documents and verification selfies on public channels, and has said it will release further material every day until the company pays.
The posts, seen on X and Telegram on 13 September 2026, follow Revolut’s confirmation earlier in the week that it disclosed customer records after accepting fraudulent information requests sent from an email account hosted on a legitimate government agency domain.
The escalation extends a case that The Crypto Times reported on 12 September 2026, after customer notices began surfacing the previous evening. Former Mt. Gox chief executive Mark Karpelès and on-chain investigator ZachXBT made the notices public, and several named users have since said publicly that they received the warnings.
What Revolut Has Confirmed
Revolut told Reuters and other outlets that it identified a “sophisticated external impersonation scam” in which an unauthorised third party used a legitimate government agency domain email to submit fraudulent requests for information. A company spokesperson said Revolut blocked the address after detection, alerted the relevant government agency, law enforcement, data protection authorities and financial regulators, and contacted the “limited” number of impacted customers directly. The firm said its systems and customer funds were unaffected.
Revolut has not published the number of customers involved, the markets affected, or the name of the government agency whose domain was used.
Customer notices, excerpts of which Karpelès posted publicly on 12 September 2026, described the request as originating from an unauthorised mailbox that sat inside official government domain infrastructure and carried valid domain authentication.
Because the messages passed standard email authentication checks, including Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC), Revolut treated them as genuine legal requests and released the files. Karpelès said he received a notice with the subject line “Urgent security update about your Revolut account” at 21:59 Coordinated Universal Time (UTC) on 11 September 2026.
Data Categories Listed in the Notices
Matching notice language across independent posts lists four groups of material that may have been disclosed.
The first covers identity details, including full name, date of birth and occupation. The second covers contact information, including postal address, email address and telephone number. The third covers document and verification data, meaning a copy of an identity document such as a passport or driving licence together with the facial verification image submitted at onboarding.
Revolut has said no biometric facial telemetry data was involved, drawing a distinction between the selfie photograph itself, which is treated as disclosed, and the derived face template used for matching, which it says was not.
The fourth category covers financial records, including account statements with International Bank Account Number (IBAN), account status, opening date and wallet reference number, withdrawal records, and full transaction histories, including Bitcoin activity recorded through Revolut’s main app and its dedicated crypto trading platform Revolut X.
Notices and company comments have not indicated that login passwords, card personal identification numbers (PINs), private keys or account balances were taken, and no stolen funds have been reported.
The Escalation and Named Individuals
On 13 September 2026, threat-intelligence account International Cyber Digest reported that the same threat actors had begun publishing sensitive customer data, including material they attributed to tennis player Alexander Shevchenko and Felix Römer, chief executive of online crypto casino Gamdom and Skinscom.
The post said the actors want Revolut to pay, intend to release more messages, data and commentary on how Revolut’s team operates, and accuse the company of handing information to countries outside its jurisdiction and of negligence around privacy. Römer replied to the post on X, writing: “Ah wtf @Revolut.”
Dark-web monitoring account DailyDarkWeb posted on 13 September 2026 that the threat actor said: “We’re gonna start releasing more and more data everyday until Revolut pays for leaking their customers.”
The same account noted that the identity of the attacker, the ransom demand, the claimed high-profile victims and the authenticity of the newly leaked material had not been independently confirmed by Revolut or law enforcement, and should be treated as threat-actor claims. No public, confirmed figure for the demanded payment has been issued by Revolut, and isolated social-media mentions of a large bitcoin demand have not been corroborated.
How the Fraudulent Request Cleared Controls
The mechanism is the part of the case that banks, exchanges and other Know Your Customer (KYC) heavy platforms are likely to study closely. The attacker did not need to breach Revolut production systems. The mailbox sat on a real government domain, and the messages carried valid SPF, DKIM and DMARC results.
Revolut’s process treated domain authentication as evidence that the request itself was lawful. Revolut has not said whether the mailbox was hijacked from outside the agency, created internally without authority, or obtained by some other route.
Security site Help Net Security noted on 14 September 2026 that the case shifts the risk model from a conventional production-network breach to an attack on the trust path used for lawful disclosure, and that independent, out-of-band verification of sensitive government requests becomes essential when the payload is identity documents, KYC images or complete financial histories.
Why the Bitcoin Records Matter
Revolut records Bitcoin activity for customers who buy, sell, or withdraw through its main app and Revolut X. Pairing a full transaction history and an internal wallet reference number with a passport image, a verification selfie, an IBAN, and a residential address produces a dossier that is more useful for targeted fraud than a typical email-and-password dump.
Address rotation on-chain does not undo that combination once the identity pack is public. A holder can rotate addresses but cannot rotate a passport photograph or a legal name.
Quinten van Welzen, Head of Marketing and Growth at Zano, a privacy-focused blockchain project, shared this comment exclusively with The Crypto Times. He said the residual risk sits with the on-chain link even if a dump campaign later stops:
“The leak might be over, but the exposure isn’t. On transparent blockchains, once an address is linked to a person, the attacker can continue to monitor the transactions indefinitely. Moving funds to a private blockchain makes it harder for the attacker to learn about the crypto holder’s future transactions, but unfortunately it doesn’t erase the history that was already exposed.”
He added, “Blockchains can’t prevent companies from leaking user data, but privacy-preserving techniques limit what information an attacker can access. Financial privacy is a basic requirement for personal security. Revealing to the world that you’re in possession of a lot of cryptocurrency could leave you subject to extortion and wrench attacks.”
What Remains Unverified
The name of the government agency, the number of affected customers, the date range over which fraudulent requests were fulfilled, the method by which the mailbox was obtained, the authenticity of the 13 September dumps and any confirmed ransom terms all remain unresolved.
Revolut is separately in the middle of a broader expansion track that The Crypto Times has covered, including conditional approval from the Office of the Comptroller of the Currency for a United States national bank charter, the delisting of Tether’s USDT stablecoin under the European Union’s Markets in Crypto-Assets regime and the launch of the euro-backed EURR stablecoin. Those corporate milestones do not change the facts of the disclosure. They do raise the compliance cost if the leak campaign continues and if fresh files keep authenticating.
Guidance for Customers Who Received a Notice
Customers who received Revolut’s 11 to 12 September notice should treat the listed data classes as exposed for practical purposes, even while the authenticity of later Telegram dumps remains unverified.
Users should watch for phishing messages that cite the incident, quote transaction history, or attach files that look like Revolut or government correspondence, and refuse to send documents or funds to anyone claiming to “secure” the leak. Revolut has said it is applying precautionary protections to affected accounts and has told customers to use official app and website channels only.
This is a developing incident. The confirmed core is narrow and serious. Revolut honoured a government-styled request that was not genuine, and the payload included KYC documents, selfies, and Bitcoin transaction histories for a limited customer set. The daily-leak campaign is a threat-actor claim now being tested in public. Until Revolut or law enforcement authenticates the new files and any payment demand, those elements should be reported as claims, not as settled fact.
Also Read: Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit, Offers Attacker 20% Bounty
