Revolut Attackers Leak Selfies and IDs as Ransom Demand Escalates

TL;DR:
- Attackers began publishing Revolut customer selfies and identity documents, threatening daily releases until the fintech pays, while exposed data may also include account statements and Bitcoin transaction histories.
- Revolut said the breach resulted from fraudulent information requests sent through an email address tied to a legitimate government agency domain, not a compromise of its systems.
- The leaks raise identity-theft and social-engineering risks even though Revolut says customer funds remain secure.
Revolut customers are facing an escalating data-extortion campaign after attackers began publishing identity documents and selfies allegedly obtained through fraudulent information requests. The leaked material reportedly includes facial-verification images and IDs belonging to affected customers, while the attackers threatened on Telegram to release more information every day until the fintech pays. The pressure campaign has moved beyond a private breach into public exposure of sensitive identity data. Revolut said the compromised information can also include full names, dates of birth, occupations, contact details, account statements and complete transaction histories, including records tied to Bitcoin transactions.
… Continue reading the full article at the original source below.


