Attackers began publishing customer records on and have threatened daily releases until the company pays.
What Revolut disclosed on and 12 as a data incident has escalated. Beginning around , the attackers began publishing stolen customer data on X and Telegram, accompanied by an explicit threat of continued daily releases until Revolut pays.
The original intrusion did not involve breaking anything. Attackers submitted fraudulent government information requests that passed SPF, DKIM and DMARC authentication checks, and Revolut honored them. The authentication layer worked exactly as designed and verified a forged request as legitimate.
What is in the published material
Security researchers tracking the leak describe the published files as including identity documents such as passports and driving licenses, facial-verification selfies, full names, dates of birth, occupation and contact details, account statements including IBAN information, and complete Bitcoin transaction histories with wallet references.
That last category is different in kind from the rest, and it is why this matters beyond a conventional fintech breach.
Why the on-chain exposure does not expire
A leaked passport can be replaced. A card number can be reissued. An address can be changed. A published mapping between a verified identity and a Bitcoin wallet cannot be undone, because the blockchain it points at is permanent and public.
The practical consequence is broader than the affected accounts. Anyone whose Revolut Bitcoin activity touched addresses they also use elsewhere may now find their wider on-chain footprint attributable, since chain-analysis techniques work outward from a single confirmed identity link. The leak does not only expose what those customers did on Revolut. It potentially deanonymizes what they did everywhere else that connects.
What Revolut has said and has not said
The company has said a limited number of customers are affected, that customer funds and core systems were not affected, and that it has notified law enforcement, government agencies and regulators.
It has not disclosed a count of affected customers, which markets are affected, or how long the window was open during which fraudulent requests were honored. Those three figures are what determine the actual scale, and none of them is public.
What comes next
The attackers have threatened further releases, which means the exposed population may be larger than what has been published so far. Whether regulators in Revolut's principal markets open formal inquiries, and whether the company discloses the scope figures it has so far withheld, are the two developments that would change the picture.
