Revolut Data Breach Extortion Site Unmasked by Researchers

The fallout from the Revolut data breach took a new turn after threat intelligence firm KELA published research tracing the extortion site used to pressure the fintech company into paying attackers. According to KELA's findings, the site was hosted on free public infrastructure and assembled in just 6.5 hours. Even more notable: files the attackers thought they had deleted were still recoverable through the site's public commit history, a detail that hands defenders and researchers a rare look inside the mechanics of a modern extortion campaign.

This discovery matters because it shows that the criminals behind the Revolut incident did not build a sophisticated, hardened operation. Instead, they leaned on quick, free tools, and in doing so left behind a trail that researchers could follow. For a breach that has already drawn scrutiny for how the attackers obtained customer data in the first place, this second chapter offers a window into just how improvised and exposed extortion infrastructure can be.

How the Extortion Site Was Built and Traced

KELA's analysis found that the extortion page did not sit on custom servers or specialized dark web infrastructure. It ran on a free, publicly accessible hosting service, the kind anyone can sign up for in minutes. The speed of deployment, just 6.5 hours from start to finish, suggests the attackers prioritized getting pressure on Revolut quickly over covering their tracks carefully.

That haste created an opening. Because the site relied on a public commit history (the record of changes made to the site's underlying code or content), researchers were able to look back at versions of the page the attackers had tried to remove. Files that were deleted from the live site were not actually gone; they remained visible in the history logs, giving KELA insight into how the extortion page evolved and what content the attackers had originally included before scrubbing it.

This kind of operational security failure is not unusual in cybercrime. Building infrastructure quickly and cheaply is often the priority for extortion groups looking to strike while a breach is still fresh news, but that speed frequently comes at the cost of leaving digital fingerprints behind.

Connecting the Extortion Site to the Original Breach

The extortion site did not appear out of nowhere. It followed Revolut's disclosure that sensitive customer data had been exposed after the company was deceived by a fake government request, which resulted in passport and personal information being handed over to an unauthorized third party. That earlier incident set the stage for the extortion attempt: once attackers had customer data in hand, they moved to build a pressure site aimed at forcing a payout from Revolut.

This sequence, a social engineering trick followed by data exposure and then extortion, reflects a common pattern in financially motivated cybercrime. Attackers rarely need highly advanced tools to succeed. A convincing fake request was enough to get sensitive data released, and a few hours on free hosting was enough to launch a public pressure campaign afterward.

What This Means For You

If you're a Revolut customer, the practical risk from this specific extortion site is less about the hosting details and more about what data may have been included in it. Extortion pages tied to breaches like this one often reference or preview stolen information, including passport numbers and account details, as leverage. The fact that researchers could recover deleted files from the site's history also means that content the attackers tried to hide, potentially including samples of the leaked data, may still be documented and analyzed by security researchers.

For everyday users, this reinforces a broader lesson about the Revolut data breach: the initial compromise happened not through a technical hack of Revolut's systems, but through deception. That means the usual advice around monitoring your accounts, watching for phishing attempts referencing this breach, and being cautious about unsolicited requests for personal information is especially relevant right now. Attackers who successfully impersonate authorities once may try similar tactics again, either against Revolut or its customers directly.

Actionable Takeaways

If you use Revolut or have been affected by this breach, consider the following steps:

  • Watch your Revolut account and linked bank accounts closely for any unfamiliar activity in the coming weeks.
  • Be skeptical of any communication, especially urgent-sounding messages, claiming to be from Revolut, government agencies, or law enforcement referencing this incident.
  • If your passport or identity documents were part of the data exposed in the earlier disclosure, consider monitoring for identity theft and be cautious about sharing copies of ID documents unless absolutely necessary.
  • Follow updates from Revolut directly rather than relying on links or files circulated in connection with the extortion site, since researchers have shown that content on these sites can be manipulated and reappear even after being deleted.

The Revolut data breach and its extortion aftermath show that even attackers with functional criminal operations can make basic mistakes that researchers can exploit. For customers, staying alert and cautious remains the best defense while the fuller picture of this incident continues to unfold.