What Happened: The Telegram Extortion Campaign Explained

A new Revolut data leak extortion campaign is unfolding in real time, and it's playing out in public. Since September 13, hackers have been posting Revolut client dossiers on Telegram at a rate of one per day. The pattern is deliberate: rather than dumping everything at once, the attackers are drip-feeding leaks while threatening to release more unless Revolut pays up.

This slow-drip approach is a classic extortion tactic. It keeps pressure on the company, generates ongoing media attention, and gives the attackers leverage to negotiate while showing they still hold more data in reserve. For Revolut customers, it also means the damage isn't a single event you can assess and move past. It's an ongoing exposure that could continue for as long as the hackers choose to keep posting.

This isn't Revolut's first brush with a data incident. The company has previously confirmed breaches tied to fake government requests that exposed customer data, including one incident where a fraudulent government email led to exposed IDs. If your data was ever part of a prior Revolut incident, it's worth assuming it could resurface here too.

What Kind of Data Is Exposed in These Dossiers

The term "client dossier" suggests something more comprehensive than a simple email and password list. In prior Revolut incidents, the sensitive data exposed has included passport scans and identity documents, the kind of information collected during standard Know Your Customer (KYC) verification that fintech apps require by law. Earlier reporting on Revolut breaches described passports leaked through a fake request and, in a separate incident, passport and Bitcoin transaction data exposed together.

That combination matters. A passport scan alone is bad. A passport scan paired with financial or cryptocurrency activity gives criminals a far more complete profile for identity theft, account takeover, or targeted phishing. Unlike a password, you can't simply reset your passport number or your transaction history. Once that kind of dossier is public, it stays exploitable indefinitely.

Why Financial Services Are Prime Targets for Extortion Hackers

Fintech companies like Revolut sit on an unusually valuable pile of data: government-issued ID documents, proof-of-address records, transaction histories, and sometimes cryptocurrency wallet activity, all in one place. That density of sensitive personal and financial information is exactly what makes extortion attacks effective. Attackers know that a company holding this much regulated, high-stakes data has strong incentives to negotiate quietly rather than risk regulatory penalties, customer churn, and reputational damage playing out daily on a public platform like Telegram.

Publishing leaks incrementally, rather than all at once, also maximizes psychological pressure on both the company and its customers. Each new daily post is a reminder that the clock is running and that more people could be affected tomorrow.

What This Means for You

If you're a Revolut customer, the most important mindset shift is this: don't wait for the company to confirm whether your specific data was included in the Telegram leaks before you act. Extortion leaks like this are often only a partial or evolving picture, and confirmation can take time. Treat your KYC data, meaning your ID documents, address history, and account details, as potentially compromised now, and take precautions accordingly.

This also isn't an isolated one-off. Revolut has faced multiple data exposure incidents recently, and if your information appeared in an earlier breach, there's a real chance it could be recirculated or combined with newer leaked material. It's worth checking your own history with the company rather than assuming this latest incident is unrelated to past ones.

Actionable Takeaways

  • Monitor your Revolut account activity closely for unfamiliar transactions or login attempts, and enable any available account alerts.
  • Be alert to phishing attempts that reference your real name, account details, or ID information, since leaked dossiers make convincing scams easier to craft.
  • If you suspect your passport or ID data has been exposed, consider contacting the issuing authority about fraud monitoring options, since document numbers can't be reset like passwords.
  • Review whether you were affected by any of Revolut's earlier data incidents, as repeated exposure increases your overall risk profile.
  • Use unique, strong passwords and two-factor authentication on your Revolut account and any linked email or financial services, so a leaked dossier alone can't be used to take over additional accounts.

The Revolut data leak extortion campaign is a reminder that once financial and identity data leaves a company's control, customers can't simply wait for a resolution. Acting early, staying skeptical of unexpected contact, and locking down your accounts now is the more reliable path to limiting the damage.