Revolut Data Breach Exposes Passports, Bitcoin Records, and Selfies
A new Revolut data breach has put sensitive customer documents into the hands of cybercriminals, who are now publishing the material in daily leaks while demanding a ransom payment. According to reporting from Blockonomi, the exposed data includes passport scans, Bitcoin transaction records, and identity verification selfies, the exact kind of personal documentation fintech apps like Revolut require during account signup and compliance checks.
The attackers have reportedly said they will continue releasing batches of stolen data on a daily basis unless their ransom demands are met. This kind of drip-feed extortion tactic is designed to maximize pressure on both the company and its customers, turning a single breach into an ongoing crisis that plays out publicly over days or weeks.
How the Breach Happened
This incident follows an earlier Revolut security lapse. As covered in previous reporting on Revolut's extortion demand after a September data breach, the company inadvertently handed over a trove of customer information to attackers who exploited access tied to a compromised email domain. That earlier episode set the stage for the extortion attempts now playing out, with hackers using the stolen data as leverage rather than simply selling it quietly on underground markets.
What makes this case notable is the type of data involved. Passport images and verification selfies are not the kind of information that can be reset like a password. Once these documents are exposed, they remain permanently compromised, since a person's face and government-issued identification cannot be changed the way a login credential can. Bitcoin records add another layer of risk, potentially linking financial activity to real identities in ways that could expose users to targeted scams or further extortion attempts.
Why This Matters for Privacy
Fintech companies like Revolut sit at an unusual intersection of financial services and identity verification. To comply with anti-money laundering and know-your-customer regulations, these platforms collect and store some of the most sensitive documents a person owns: passports, driver's licenses, and biometric selfies used to confirm identity matches. When that data is breached, the fallout extends far beyond a typical password leak.
Ransom-driven leaks like this one also raise a difficult question for affected users: paying attackers rarely guarantees data won't be released or resold anyway, and companies that refuse to pay may see customer information trickle out regardless. For everyday users, this means the practical response has to focus on damage control and vigilance rather than waiting to see how the standoff between Revolut and the hackers resolves.
The use of daily leaks as a pressure tactic is also a reminder that breach notifications and public reporting can lag behind what's actually happening. Customers may not know the full scope of what's been exposed until attackers choose to publish it, which is why proactive monitoring matters more than relying solely on official updates.
What This Means For You
If you're a Revolut customer, or a user of any fintech platform that handles identity verification, this breach is a useful prompt to take a few concrete steps:
- Check your account activity. Log in and review recent transactions for anything unfamiliar, and enable transaction alerts if you haven't already.
- Watch for phishing attempts. Leaked passport and selfie data can be used to craft convincing scam messages that impersonate Revolut support or claim to verify your identity. Be skeptical of unsolicited requests for further personal information.
- Consider identity theft protections. Since passport scans can't be reissued the way a password can, monitoring services that flag misuse of your identity documents may be worth exploring.
- Stay alert to follow-up communications from Revolut. Companies dealing with active extortion situations often issue updated guidance as investigations progress, so checking official channels periodically is worthwhile.
Final Thoughts
The Revolut data breach highlights a growing pattern in cybercrime: rather than quietly selling stolen data, attackers are increasingly using it as an ongoing lever for extortion, releasing information in stages to maximize pressure. For a company that handles the financial and identity data of millions of customers, that approach turns a single security failure into a prolonged privacy crisis for everyone whose documents were caught up in it.
While Revolut works through its response, affected users shouldn't wait passively. Reviewing account activity, staying alert for phishing attempts tied to the leaked documents, and monitoring for signs of identity misuse are practical steps that can reduce the fallout, regardless of how the ransom situation is ultimately resolved.




