# Revolut Extortion Escalates: Hackers Weaponize Fake Police Requests to Leak Passports

> The Revolut data breach has escalated into an active extortion campaign, with hackers leaking customer passports obtained through a fake EDR attack.

- Canonical URL: https://coreiten.com/en/article/revolut-extortion-escalates-hackers-weaponize-fake-police-requests-to-leak-passports
- Language: en
- Section: Security
- Author: Sami
- Published: 2026-09-14T18:02:18+03:00
- Modified: 2026-09-14T18:02:18+03:00
- Publisher: CoreITen (https://coreiten.com)
- Keywords: Revolut data breach, fake EDR attack, Mark Karpelès, Lapsus$, Bitcoin, Apple, Meta

## Summary

A Revolut data breach escalated into an extortion campaign after hackers weaponized a fraudulent emergency data request to leak sensitive customer passports and transaction histories.

- High-profile victims identified include former Mt. Gox chief executive Mark Karpelès, tennis player Shevchenko, and Gamdom CEO Römer.
- The exposed information includes full names, dates of birth, occupations, passport and driving-licence copies, verification selfies, and Bitcoin activity records.
- Attackers executed the breach by emailing a request from an address hosted on a legitimate government agency's domain to bypass standard security protocols.
- An FBI warning issued in November 2024 highlighted a spike in similar attacks where hackers used compromised police accounts to extract user data.
- Mitigation strategies include implementing out-of-band callback verification by contacting requesting agencies through publicly published phone numbers.

**Why it matters:** This incident exposes a critical industry vulnerability where emergency data request speed optimizations are exploited by bad actors, threatening fintech expansion into banking and stablecoins.

---

The Revolut data breach has rapidly escalated into an active extortion campaign, with attackers publishing sensitive customer passports and selfies online. Fintech users and cybersecurity professionals monitoring the fallout must now navigate a scenario where immutable identity documents and crypto transaction histories are being weaponized for ransom.

The attackers have taken to Telegram, threatening to release more customer data daily until the financial institution pays a ransom. While Revolut has not confirmed the ransom amount or the total number of affected users, high-profile clients, including former Mt. Gox chief executive Mark Karpelès, tennis player Shevchenko, and Gamdom CEO Römer, have been identified among the victims.

The exposed data carries severe extortion value because it cannot be easily reset like a password. Compromised information includes full names, dates of birth, occupations, postal and email addresses, phone numbers, passport and driving-licence copies, and verification selfies. Furthermore, the leak exposes account statements, IBANs, and full transaction histories, including specific records of Bitcoin activity.

Unlike a traditional database hack, this breach was executed through a fraudulent emergency data request (EDR). The attackers emailed a request for customer records using an address hosted on a legitimate government agency’s domain. Because the correspondence passed internal checks by originating from real agency infrastructure, the unauthorized sender successfully bypassed standard security protocols.

Revolut has since blocked the address and notified law enforcement, data-protection authorities, and financial regulators. However, this fake EDR vector is a systemic industry flaw with a documented history. In 2021, teenage hackers affiliated with the Recursion Team and Lapsus$ groups used compromised police accounts to extract user data from Apple, Meta, and Discord, prompting a specific FBI warning in November 2024 about a spike in these attacks.

### How to Mitigate Fake EDR Attacks

Security teams and regulated brokers must implement stricter verification protocols to counter the asymmetry of fraudulent requests. Relying solely on domain authentication is no longer sufficient when dealing with the roughly 18,000 law-enforcement jurisdictions in the United States alone.

- Implement out-of-band callback verification by contacting the requesting agency through a publicly published phone number.
- Log and cross-check every incoming law-enforcement request to identify suspicious patterns or first-time contacts lacking history.
- Utilize pooled intelligence across financial firms to detect if the same fraudulent requester is approaching multiple institutions simultaneously.

### The Verification Gap Threatening Fintech Expansion

The escalation of this breach exposes a critical vulnerability in how financial institutions handle the friction between legal compliance and data security. Emergency data requests are intentionally designed for speed to address imminent threats, often bypassing the need for a court order. Every optimization for speed in this channel inherently creates a verification gap that state-backed actors and extortionists are now actively exploiting.

This incident lands at a particularly sensitive time for Revolut as it expands into United States banking and stablecoins after securing preliminary approval for a national bank. Building a business on holding immutable identity and transaction data requires a zero-trust approach to external communications. If a single compromised police email account can bypass the defenses of a major fintech platform, the entire industry must shift from isolated verification to mandatory, cross-industry cryptographic proof of identity for all law enforcement requests.

## Sources

- [financefeeds.com](https://financefeeds.com/revolut-data-breach-extortion-leaked-ids-ransom/)
