Sign up
Subscribe
Home / news / Revolut data leak exposes Gamdom and Skins(.)com owner details after phishing attack
news

Revolut data leak exposes Gamdom and Skins(.)com owner details after phishing attack

Revolut confirmed that customer data was passed to an unauthorized third party after attackers sent fake legal requests from a real government email domain. For high-risk operators, the practical point is simple: once a PSP holds KYC files, bank details, and transaction histories, a payment incident can turn into a source of identity data for players, executives, and VIP clients.

  1. According to Revolut, the attackers used messages that passed standard authentication checks, including SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting and Conformance), so staff treated them as legitimate legal requests and disclosed data.
  2. The first customer alerts, with the subject line “Urgent update on your Revolut account security,” started arriving on the evening of 11 September at around 21:59 UTC. One copy was publicly posted by former Mt. Gox CEO Mark Karpelès, who received the same message. Revolut officially confirmed the breach on 12 September.
  3. Financial Times reported that Revolut contacted about 680 customers whose data was affected. The company has not disclosed the exact number of impacted users, the name of the government agency whose domain was used, or the country where the attack took place.
  4. On-chain investigator ZachXBT said the attack appears to have targeted wealthy customers. The exposed material includes KYC data such as passports and driver’s licenses used during registration, customer photos for identity verification, names, dates of birth, addresses, phone numbers, IBANs (International Bank Account Numbers), withdrawal history, and full transaction history, including bitcoin trades.
  5. On 13 September, International Cyber Digest said on X that the attackers had started publishing the stolen data directly. Files circulating online reportedly belong to Felix Römer, CEO of Gamdom and Skins(.)com, as well as tennis player Alexander Shevchenko. Earlier mentions included streamer WatchGamesTV, who has 115,000 Twitch subscribers, and employees of the iGaming platform Yeet, but those links have not been confirmed.

Revolut said its own systems and customer funds were not affected. The company also said it blocked the address used in the attack and notified government authorities, law enforcement, and regulators. In a Telegram channel, the attackers claimed they would publish “more and more data every day” until Revolut pays the demanded 10,000 BTC ($768 million).

Weekly high-risk digest

Regulation, sanctions and payment news across your verticals — once a week, free.

Please check your inbox and click the link to confirm your subscription.

Please enter a valid email address!