TL;DR
▶ The attackers who obtained Revolut customer data via a fake government request on September 12 have begun publicly posting stolen passports and selfies on X and Telegram, starting September 13.
▶ Their demand: “We are going to start releasing more and more data every day until Revolut pays.” Revolut has not confirmed whether it will pay.
▶ First confirmed victims in the public leak: tennis player Alexander Shevchenko and Felix Romer, CEO of crypto casino Gamdom. Both had passports and identity selfies published without consent.
▶ This is now a double extortion operation: data was obtained through a social engineering attack, and the threat actors are now using public exposure of victims as leverage against the company.
▶ Revolut has confirmed the breach is due to a sophisticated external impersonation scam. It has not stated whether it will pay or refuse the ransom demand.
▶ Every day Revolut does not pay, more customers face having their passports, selfies, IBANs, and Bitcoin transaction histories published on public channels.
Two days after Revolut confirmed it had handed sensitive customer data to a fake government request, the attackers escalated. On September 13, 2026, threat intelligence account International Cyber Digest reported on X that the threat actors had stopped waiting and begun publishing stolen customer data on public channels: selfies and copies of identity documents, starting with two named individuals. Tennis player Alexander Shevchenko and Felix Romer, CEO of online crypto casino Gamdom, had their passports and identity verification selfies published without their consent.
The message the attackers posted on Telegram was unambiguous: “We’re going to start releasing more and more data every day until Revolut pays for leaking their customers.” The phrasing is a textbook double extortion structure: obtain the data, publish a sample to prove possession, threaten to release the full dataset to pressure payment. What makes it unusual is the framing. The attackers are positioning themselves not as criminals who stole from Revolut, but as aggrieved parties demanding Revolut compensate the customers whose data it allowed to be taken. Whether that is cynical misdirection or a genuine grievance does not change the harm to the people whose documents are now on public channels.
Revolut told Cointelegraph on September 13 that the breach affected a “limited number” of customers and that its systems and customer funds remain unaffected. It has not commented publicly on the extortion demand, has not stated whether it will pay, and has not named a figure the attackers are requesting. The silence on payment terms is standard practice during active extortion negotiations. It also means every Revolut customer whose data was included in the original fraudulent disclosure now faces an unknown countdown to public exposure.
What Is Double Extortion and Why Is This Attack More Dangerous Than a Standard Breach?
What is double extortion?
Double extortion is a ransomware and data theft tactic where attackers first exfiltrate sensitive data, then threaten to publish it publicly unless the victim pays. Unlike traditional ransomware, which only encrypts data and demands payment to restore access, double extortion adds the threat of public exposure as a second lever. The victim faces two distinct harms: the operational disruption of losing access to data, and the reputational and legal harm of that data being exposed. In the Revolut case there is no encryption, only the stolen data. The entire leverage is public exposure of individual customers, which the attackers are now executing.
The Revolut extortion differs from a typical corporate double extortion in an important way. Standard double extortion targets the company: publish embarrassing internal data, leak source code, or release trade secrets to harm the company’s business. The Revolut attackers are targeting individual customers directly by naming them and posting their personal documents. That is a more aggressive tactic. It harms real people immediately and publicly, creating visible evidence that the threat is credible, while simultaneously pressuring Revolut through the reputational cost of each new victim named.
For the specific customers whose data was obtained in this breach, the daily leak threat is not abstract. The data package includes passports, selfies, home addresses, phone numbers, email addresses, IBANs, and complete Bitcoin transaction histories. Each of these elements is harmful in isolation. Together they represent a complete targeting and identity package. A daily leak of a new customer’s full data set, published on public channels with their name attached, creates permanent, searchable, irremovable harm to that person’s security and privacy.
Timeline: How the Revolut Incident Escalated in 72 Hours
Revolut Incident Timeline: September 11-14, 2026
Sept 11 evening
Revolut begins notifying affected customers by email. Excerpts of the notification shared on X by Mark Karpeles and ZachXBT, revealing the scope of exposed data including Bitcoin transaction histories.
Sept 12 morning
Story goes public. TechCrunch, The Block, and BNO News confirm breach through Revolut spokesperson. Revolut confirms a sophisticated external impersonation scam using a fake government agency email that passed SPF, DKIM, and DMARC authentication. Marc Zeller (Aave Chan Initiative) confirms he was also affected.
Sept 12 afternoon
Revolut tells Cointelegraph breach affected a limited number of customers. Systems and funds unaffected confirmed. Agency identity still not disclosed.
Sept 13
International Cyber Digest reports on X that attackers have begun publicly posting stolen customer data: passports and selfies of tennis player Alexander Shevchenko and Gamdom CEO Felix Romer published on public channels. Attackers post on Telegram: will release more data every day until Revolut pays.
Sept 14
Extortion demand ongoing. Revolut has not publicly responded to payment demand. Daily leak threat active. More customers at risk of public exposure.
Sources: Cointelegraph Sep 14 2026, CryptoTimes Sep 14 2026, TechCrunch Sep 12 2026, International Cyber Digest X post Sep 13 2026 | @cryptonewsbytes
Who Are Alexander Shevchenko and Felix Romer? Why Name Them?
Alexander Shevchenko is a professional tennis player. Felix Romer is the CEO of Gamdom, an online crypto casino and skin trading platform. Neither is a major public figure in the traditional sense of a politician or executive. Their names were published specifically because they are recognisable enough in their respective communities to generate attention and prove the data is real, while being private individuals who have not consented to public disclosure of their identity documents.
The selection of these specific individuals in the first leak is a calculated move. Publishing the passport and selfie of a tennis player and a crypto industry CEO creates immediate, verifiable, newsworthy harm. Other media will cover it. The victims will confirm it. That confirmation proves to Revolut and to the broader market watching that the attackers’ possession of the data is genuine and the threat is credible. It is a proof-of-possession demonstration designed to maximize the pressure on Revolut to pay before more customers are exposed.
Gamdom CEO Felix Romer has been contacted by Cointelegraph for comment per its reporting as of September 14. No response was published at time of writing. Revolut has also been contacted and has not commented on the extortion demand specifically.
Should Revolut Pay? The Extortion Dilemma Every Breached Company Faces
The standard advice on paying ransoms
Law enforcement agencies including the FBI, the UK National Crime Agency, and INTERPOL consistently advise against paying ransoms in extortion situations. The reasons are consistent: payment does not guarantee the attacker deletes the data or stops publishing it, payment funds further criminal operations, and payment creates an incentive to target the same organisation again. The UK National Cyber Security Centre specifically notes that organisations that pay are frequently targeted again because they are known to pay. Revolut has not indicated whether it is considering payment.
The specific dynamics of the Revolut situation make the standard advice particularly relevant. The attackers obtained data about an unknown number of customers. They have published samples from two. The full dataset, if published, would harm every person in it regardless of whether Revolut pays. Payment does not unring a bell. The data that has already been published cannot be unpublished. The individuals whose passports and selfies appeared on September 13 have already suffered the harm that payment was presumably meant to prevent.
The second reason the standard advice holds here is the nature of the leverage. The attackers claim they are demanding payment because Revolut leaked customer data. But Revolut did not leak data voluntarily. It was deceived. The attackers are the ones who submitted the fraudulent request that caused the leak. The framing of “Revolut pays for leaking their customers” is an attempt to transfer moral and financial responsibility from the attackers to the company. Payment would validate that framing and create a template for future attacks: socially engineer a fintech into releasing data, then extort them using the data as leverage.
From a regulatory standpoint, Revolut has notified data protection authorities, law enforcement, and financial regulators, as confirmed in its customer notice. Those notifications create oversight that constrains how Revolut can respond to the extortion demand. Paying a ransom to criminal actors after a data breach is legally complex in multiple jurisdictions and may itself require regulatory disclosure.
What This Means for Every Revolut Customer Who Got the Notification
If you received Revolut’s customer notification about this incident, the escalation to public leaks changes your situation materially. The original breach article CNB published on September 12 covered the immediate steps to take. With active daily leaks now confirmed, several of those steps become more urgent.
The Bitcoin transaction history element is the most dangerous specific exposure for crypto holders. Your Revolut Bitcoin records, combined with your home address and passport, give an attacker the targeting package for a wrench attack. The wrench attack risk is proportional to the visible holdings in your transaction history. If your Revolut account shows significant Bitcoin activity, your physical security risk is elevated from the moment your data is published.
The identity document exposure creates a second distinct risk: deepfake-assisted identity fraud. Your passport photo and a selfie taken for liveness verification are now potentially public. Combined with your date of birth, address, and account details, an attacker has everything needed to attempt account takeover at banks and services you use outside Revolut, particularly those whose identity verification can be attacked using the biometric data you provided to Revolut during KYC.
The Regulatory Consequences: Revolut’s Banking Charter Is Now at Risk
CryptoTimes’ coverage of the escalation noted that analysts believe the ongoing leak situation could spur regulatory scrutiny that affects Revolut’s US banking charter application, which has been in progress and represents a major strategic objective for the company. Revolut obtained a UK banking licence in 2024 after a three-year application process. A US banking charter would represent a significant expansion of its operating model and is understood to be a priority for the business.
A data breach in which customer data was exposed through a social engineering attack, followed by an active extortion operation publishing customer documents on public channels, is precisely the kind of event that banking regulators evaluate when assessing whether an applicant meets the operational risk management standards required for charter approval. The UK Financial Conduct Authority and Prudential Regulation Authority are both aware of the incident. The US Office of the Comptroller of the Currency, which handles banking charter applications, will be watching how Revolut manages the extortion escalation.
This is not speculative. The GDPR framework under which Revolut operates as a UK-based entity requires notification to the Information Commissioner’s Office when a breach may result in a risk to individuals, which Revolut has already done. The ICO can issue fines of up to 4% of global annual turnover for GDPR breaches. For Revolut, which has been valued at approximately $45 billion, that ceiling is substantial. Whether the ICO determines Revolut’s response was appropriate, given that the company was deceived rather than negligent, will shape the regulatory outcome.
Frequently Asked Questions
Are the Revolut attackers now leaking customer data publicly?
Yes. On September 13, 2026, threat actors who obtained Revolut customer data through a fraudulent government impersonation attack began publishing stolen customer documents on public channels. The first published data included selfies and passport copies of tennis player Alexander Shevchenko and Gamdom CEO Felix Romer, shared via an International Cyber Digest X post. The attackers stated on Telegram they will release more customer data every day until Revolut pays.
What is the attackers’ ransom demand to Revolut?
The attackers stated on Telegram that they will release more customer data every day until Revolut pays, framing the demand as compensation for the company leaking customer data. The specific amount demanded has not been publicly reported. Revolut has not publicly confirmed whether it is considering or refusing payment. Law enforcement and data protection authorities have been notified.
Who had their data published in the Revolut leak?
The first confirmed individuals with data published publicly are tennis player Alexander Shevchenko and Felix Romer, CEO of online crypto casino Gamdom. Their passport copies and identity verification selfies were shared on X and Telegram on September 13, 2026. The attackers stated these are the first of many and that more customer data will be published daily.
Should Revolut pay the ransom?
Law enforcement agencies including the FBI, UK National Crime Agency, and INTERPOL consistently advise against paying ransoms. Payment does not guarantee the attacker deletes the data or stops publishing. Payment funds further criminal operations. Organisations that pay are frequently targeted again. The data already published on September 13 cannot be removed regardless of payment. Revolut has not commented on whether it is considering payment.
If I received the Revolut breach notification, is my data going to be published?
The attackers have stated they will continue publishing customer data daily. Revolut has not confirmed the total number of affected customers or confirmed whether payment would stop the leaks. If you received the breach notification, you should assume your data may be published and take the protective steps outlined in CNB’s September 12 breach coverage as a matter of urgency, particularly regarding physical security if your Bitcoin transaction history shows significant holdings.
Further Reading
CNB’s breakdown of how fraudulent government email requests passed Revolut’s authentication checks, what records were exposed, and reactions from Marc Zeller and ZachXBT on the targeting of high-net-worth users.
The Hacken Q2 2026 report on how crypto is lost. Social engineering and operational failures account for the majority of losses. The Revolut breach sits squarely in this category.
A parallel government impersonation campaign active in August 2026: fake IRS letters using QR codes and vishing to drain crypto wallets. Two separate government impersonation attacks running at the same time.
The Hacken Q2 2026 report covering operational failures as the dominant crypto loss vector. The Revolut incident is the most significant social engineering attack on a regulated fintech in 2026.
Sources: Cointelegraph September 14 2026 (primary: ct.com/news/revolut-attackers-threaten-daily-customer-data-leaks), International Cyber Digest X post September 13 2026 (primary: attackers Telegram message and first leak), CryptoTimes September 14 2026 (US banking charter risk analysis), TechCrunch September 12 2026 (original breach confirmation), Cointelegraph September 12 2026 (Revolut spokesperson statements), blockonomi.com September 14 2026 (extortion framing analysis) | Published September 14, 2026 | CryptoNewsBytes.com | Not financial advice.

