ThreatPaper
Data BreachSocial EngineeringHigh

Revolut breach: a compromised Italian government mailbox, crypto de-anonymisation trick, and two disowned ransom demands

By Sethu Satheesh · 17 Sept 2026 · 27 min read

Threat Actor: "iamnotavillain" (self-identified, unverified claims); a separate, disowned persona ("Revolut Smilik") responsible for a disproven earlier ransom figure · Target: ~680 reported Revolut customers across 31 attacker-claimed countries; the Prefettura di Reggio Calabria's certified-mail system

Source: cybelangel.com


Executive Summary

Revolut answered a fraudulent government data request and handed over identity documents, financial histories and verification selfies for roughly 680 customers — a number the fintech itself has never confirmed, attributed instead to the Financial Times and independently repeated by City AM and by Italian outlets sourcing people close to the bank123. What makes this incident worth a long paper rather than a short one is not the disclosure itself, which by the standard of 2026 banking breaches is small. It is that nothing about it required breaking anything. The request arrived from entilocali.prefrc@pec.interno.it, a real, legally-binding certified mailbox belonging to the Prefettura di Reggio Calabria, an Interior Ministry office in southern Italy, and it passed every authentication check a bank's mail system runs, because the domain genuinely was what it claimed to be34. Revolut's own framing — "we were not hacked" — is true and is also, as one detailed independent analysis put it, "the narrowest possible reading of what happened," since UK and EU data-protection law defines a personal data breach as including unauthorised disclosure, full stop, no intrusion required, and Revolut itself understood this well enough to self-report to regulators rather than treat it as a customer-service matter2.

Who did this, how they got into the Italian government mailbox, and how they picked their targets are three separate questions with three different evidentiary standards, and conflating them is how most of the coverage of this story went wrong in its first week. On the compromise mechanism: a named threat-intelligence firm, Hudson Rock, reports it is aware of more than 300 compromised credential sets tied to the pec.interno.it domain circulating in infostealer logs, and assesses it as "highly unlikely" the attacker personally infected the specific employees involved — more likely they purchased or reused existing stolen-credential logs and are now claiming a bespoke six-month RAT operation to make the story more dramatic5. Independent Italian cybersecurity journalism, led by Pierluigi Paganini at Security Affairs working with local researchers, states plainly that "publicly available information is not yet sufficient to establish how the attackers obtained access to the Italian PEC accounts," and flags an unresolved detail that nobody else in the coverage caught: the fraudulent email carried a second, different pec.interno.it address in copy, raising the question of whether a second government mailbox was also compromised or was simply added to make the request look like routine inter-agency correspondence4. On targeting, an independent research group calling itself Duel — not the attacker, not Revolut — reports that the operation worked by sending Revolut hundreds of cryptocurrency transaction IDs and blockchain deposit addresses already known to belong to high-value accounts, and asking the bank to attach real identities to them: a "spray and pray" de-anonymisation request dressed up with citations to the EU's real European Investigation Order mechanism, rather than a hand-picked list of named individuals4. Revolut answered every one.

The extortion that followed is where the record gets genuinely contradictory, and the contradiction is itself the finding. On 13 September a Telegram channel began publishing customer dossiers with a demand of 10,000 Bitcoin — roughly $780 million — attributed by most outlets to a persona close to the name "Revolut Smilik"67. By 16–17 September, the group that actually claims the breach and runs its own site, "iamnotavillain," explicitly disowned that figure, saying it came from "an impersonator and scammer who used to work with us [who] took a small sample we handed him and is now claiming the breach as his," and posted its own, much smaller demand: 6,000 Monero, about $3 million, with a 24-hour deadline8910. Revolut's position throughout, given separately to Reuters, the Financial Times and SecurityWeek, is that it "has not received any direct contact or demand from the individuals or group making these claims"85 — meaning the $3 million figure that ran as "Revolut faces a ransom demand" in dozens of headlines was posted publicly on the attacker's own site, not delivered to the bank.

This is also not Revolut's first time. In September 2022 a social-engineering attack exposed 50,150 customers worldwide, 20,687 of them in the EEA, and drew a GDPR investigation from Lithuania's State Data Protection Inspectorate, the lead authority for Revolut Bank UAB, the Lithuania-licensed entity that also handled the fraudulent requests in this incident1112. Separately, in late 2021 into 2022, a flaw in the gap between Revolut's US and European payment systems let organised groups trigger erroneous refunds and pull roughly $20 million out through ATM withdrawals before it was caught13. Three incidents, three different mechanisms, one recurring root cause: a human process trusted the wrong signal at the wrong moment.

Verification of Claims

  1. Claim: Around 680 Revolut customers were affected. → Assessed, Not Confirmed → Revolut has never given a number, describing it only as "a limited number of customers"11410. The figure originates with the Financial Times and was independently repeated by City AM and by MilanoFinanza and Il Fatto Quotidiano citing sources close to the bank; Euronews' headline uses "700" while its own body text says "around 680," showing even converging reporting hasn't fully settled the exact number2915.

  2. Claim: Attackers demanded 10,000 Bitcoin (~$780 million) for the stolen data. → False → Widely reported 13–15 September and attributed to a persona near "Revolut Smilik"67. The group that actually claims the breach and controls the data, "iamnotavillain," explicitly disowned this figure to press, attributing it to "an impersonator and scammer who used to work with us" who "took a small sample we handed him and is now claiming the breach as his"10. CybelAngel's independent analysis states plainly that the figure "originates in threat-actor posts and social-media amplification" with "no independently corroborated amount," and that repeating it as fact means "republishing an extortionist's press release under their own masthead"2.

  3. Claim: Revolut is "facing" a $3 million ransom demand. → Assessed, Not Confirmed → "iamnotavillain" posted a public ultimatum of 6,000 XMR (~$3 million), 24-hour deadline, on its own site on 16 September89. But per Reuters, the Financial Times and a direct query from SecurityWeek, Revolut's consistent position is: "Revolut has not received any direct contact or demand from the individuals or group making these claims"85. The demand was public, not delivered — a distinction most coverage collapsed.

  4. Claim: The attacker ran a six-month RAT operation against Italian law enforcement to obtain the mailbox. → Unverified → This is the attacker's own account, given to International Cyber Digest and repeated via SecurityWeek/Hudson Rock and a Finextra opinion piece1057. Hudson Rock, a named threat-intelligence firm with direct visibility into infostealer-log markets, assesses the opposite: it is aware of 300+ credential sets tied to pec.interno.it already circulating, and states "we assess that it is highly unlikely the hacker actively infected these specific employees themselves. Instead, they likely purchased or utilized existing Infostealer logs containing these credentials, attempting to obfuscate their true method of initial access"5. Security Affairs independently concludes that public information "is not yet sufficient to establish how the attackers obtained access"4. Three different framings — RAT, infostealer purchase, and openly unknown — sit side by side in the reporting; none has displaced the others.

  5. Claim: The attacker holds 147GB of data from Italian law enforcement systems, separate from the Revolut data. → Unverified → Made by "iamnotavillain" to International Cyber Digest and repeated widely16104. Security Affairs is explicit: "This claim has not been independently verified and should therefore be treated separately from the elements of the Revolut incident that have already been confirmed" — and notes that if true, it would mean a government-infrastructure compromise far larger than one abused mailbox4.

  6. Claim: The attacker targeted specific high-net-worth individuals by name. → Assessed, Not Confirmed (mechanism), Unverified (that names were known in advance) → Duel's research, reported via Security Affairs, describes a "spray and pray" method: submitting large numbers of cryptocurrency transaction IDs and deposit addresses and asking Revolut to attach identities to them, rather than a pre-existing named list4. CybelAngel's independent analysis flags this as the single most important unanswered question in the whole incident — "So where did the target list come from?" — and states no reporting, including Revolut's own, has addressed it: "the 680 should therefore be treated as a floor on what the attacker knew rather than a ceiling"2.

  7. Claim: Specific named individuals — a Barcelona footballer, a tennis player, crypto executives — are confirmed victims. → Unverified, and internally inconsistent → International Cyber Digest reported the footballer as Georges Mikautadze17. A separate Finextra piece, also citing the attacker, names tennis player Alexander Shevchenko instead, alongside Gamdom CEO Felix Römer7; govinfosecurity's reporting, also sourced to the same general thread of claims, names Felix Romer and Marc Zeller but not either athlete10. Mark Karpelès is the one name that is independently corroborated: he confirmed to press that he personally received a Revolut breach notification and published excerpts of it — self-disclosure by a recipient, not verification of the attacker's list2. CybelAngel's analysis explicitly declines to repeat the other names, noting they "remain purely actor-attributed"2 — this paper does the same for all but Karpelès.

  8. Claim: The leaked material is authentic. → Partially Corroborated → Recorded Future News reported that one customer whose data was posted as breach "proof" did not dispute its authenticity in a subsequent social-media post — one sample2. No government body or Revolut has authenticated any of the published material, and "not all of the details contained in the actor's posts could be confirmed by the journalists examining them"2.

Timeline

Date Actor Event Source
Late 2021 – early 2022 Organised criminal groups Exploit a flaw between Revolut's US and EU payment systems; ~$23M stolen, ~$20M net loss 13
Sep 2022 Unknown (social engineering) Prior Revolut breach: 50,150 customers exposed worldwide, 20,687 in the EEA; Lithuania's SDPI opens a GDPR probe 1112
~May 2026 (attacker claim, unverified) "iamnotavillain" Six-month operation against Italian government mail systems said to begin 104
24 Jul 2026 Revolut Screenshot cited by Il Post shows Revolut confirming it had sent "all the documents" requested 3
3 Sep 2026 OCC (US) Revolut receives conditional approval for a US national bank charter — the regulatory backdrop the breach lands on eight days later 18
2026 (undated) Revolut Fraud identified; bank verifies directly with Italian authorities, who deny sending the requests; address blocked 219
11 Sep 2026 Revolut Affected customers notified directly by email 2
12 Sep 2026 Revolut Breach confirmed publicly to TechCrunch and Reuters 12
13 Sep 2026 Persona (disowned by "iamnotavillain") Telegram leak begins; 10,000 BTC (~$780M) demand circulates 26
14 Sep 2026 International Cyber Digest First contact with "iamnotavillain"; country list and named-victim claims begin circulating on X 1017
14 Sep 2026 Press BleepingComputer, Help Net Security detail disclosed data categories; ZachXBT flags high-net-worth targeting 1420
15 Sep 2026 ICO / FCA UK regulators confirm engagement 6
15 Sep 2026 Korra / Duel "Spray and pray" blockchain-deposit-address mechanism reported 4
15–16 Sep 2026 Italian press Reggio Calabria prefettura's PEC mailbox identified; Polizia Postale, Bank of Italy, ACN, Garante confirmed investigating 192115
16 Sep 2026 Procura di Reggio Calabria Criminal investigation opened: unauthorised computer access, computer fraud 1916
16 Sep 2026 "iamnotavillain" Disowns the 10,000 BTC figure; posts its own 6,000 XMR (~$3M) / 24-hour ultimatum; claims 147GB from Italian law enforcement 9104
16 Sep 2026 Security Affairs Identifies a second, uninvestigated PEC address CC'd on the fraudulent email 4
16 Sep 2026 Hudson Rock Reports 300+ pec.interno.it credentials already in infostealer-log circulation; assesses the RAT narrative as likely obfuscation 5
16–17 Sep 2026 Revolut States to Reuters, FT and SecurityWeek it received no direct contact from the claimants 85
17 Sep 2026 Press Euronews, SecurityWeek publish fullest consolidated accounts to date 95

Attack Anatomy

Initial access: an unresolved question, not a confirmed one

There is no confirmed technical account of how the attacker obtained control of, or access to, the Prefettura di Reggio Calabria's PEC mailbox. Three claims exist and they do not agree. The attacker, via International Cyber Digest, describes a deliberate six-month campaign: compromising "the IT infrastructure of agents of the Italian government, planting remote access trojans on the agents' machines" before using that foothold to operate genuinely functioning government mail systems from the inside107. A named threat-intelligence firm, Hudson Rock, which tracks infostealer-log markets directly, reports the opposite reading: it already had visibility into "more than 300 compromised credentials associated with pec.interno.it" circulating in stolen-credential logs before this story broke, and its assessment is that it is "highly unlikely the hacker actively infected these specific employees themselves. Instead, they likely purchased or utilized existing Infostealer logs containing these credentials, attempting to obfuscate their true method of initial access"5. Security Affairs, working with independent Italian researchers, declines to pick a side: "Some reports have referred to infostealers and compromised accounts, but publicly available information is not yet sufficient to establish how the attackers obtained access to the Italian PEC accounts. It is also unclear whether multifactor authentication was enabled on the affected accounts and whether attackers obtained valid credentials, session tokens or other authentication material"4. Treat every account of "how they got in" — including this one — as narrative until PEC logs and authentication records are made public.

The fraudulent request

Whatever got the attacker into the mailbox, what they did with it is well documented. Requests went out from entilocali.prefrc@pec.interno.it, a genuine certified-mail address of the Prefettura di Reggio Calabria, an Interior Ministry provincial office, signed in the name of the Polizia Postale — Italy's cybercrime police, the same unit that ended up investigating the fraud319. The messages cited real legal instruments, including a purported Milan prosecutor's investigation and the European Investigation Order, the genuine cross-border EU legal mechanism under Directive 2014/41, deployed here fraudulently34. Security Affairs identified one detail no other outlet caught: the fraudulent email carried a second, different pec.interno.it address in copy — a detail that could make a request look like routine correspondence between government offices, and that raises an unresolved question of whether a second mailbox was compromised or was simply added for credibility4. Revolut has not published the actual header data (SPF/DKIM/DMARC results) that would let outsiders check this claim directly; what is public rests on secondary reporting2.

Target selection

Independent research group Duel, working separately from both Revolut and the attacker, reports the operative mechanism: the fraudulent requests carried hundreds of cryptocurrency transaction identifiers and blockchain deposit addresses already associated with high-value activity, and asked Revolut to match them to real customer identities — a "spray and pray" de-anonymisation approach rather than a pre-existing named target list4. This is consistent with what was actually disclosed: full Bitcoin transaction histories were part of the file for every affected customer, and onchain investigator ZachXBT, who first surfaced the customer notification, independently assessed the incident as "limited in scale but aimed at high-net-worth users"202. It does not answer where the transaction IDs and deposit addresses themselves came from — prior leaked data, commercial blockchain-analytics tooling, or something else — a gap CybelAngel's analysis calls the most consequential open question in the entire case2.

Verification, in the wrong order

According to Revolut's own customer notification, the bank eventually verified the requests by contacting the Italian authorities directly — and it was Revolut that told the agency its identity was being abused, not the reverse219. CybelAngel's framing is precise: "The verification step capable of stopping this attack therefore existed within the organisation, was understood by the people who performed it, and worked exactly as intended when it was finally carried out. It was simply executed in the wrong order, after the data had already left, at which point its only remaining function was forensic"2.

Extortion

Once the breach went public, two distinct and disputed extortion tracks followed. A Telegram persona, near the name "Revolut Smilik," began publishing material on 13 September and was associated with the 10,000 BTC figure26. "iamnotavillain," which controls the actual leak site, disowned that figure on 16 September as the work of "an impersonator and scammer who used to work with us," and issued its own public, much smaller demand — 6,000 XMR, ~$3 million, 24 hours — never delivered to Revolut directly, per the bank8910.

Loading diagram...

Threat Actor Profile

  • Name / alias: "iamnotavillain" — controls the leak site and the material, in direct contact with International Cyber Digest since 14 September1017. A separate, disowned persona near "Revolut Smilik" is responsible for the earlier 10,000 BTC claim and has not been heard from independently since being disowned610.
  • Attribution confidence: Low. No individual, nationality, or known prior group affiliation has been established by any government, Revolut, or independent researcher. "iamnotavillain" is a self-adopted handle.
  • Motivation: Financial extortion. The group frames its public ultimatum around an accusation that Revolut "allowed customer data to leave its own jurisdiction" — a framing CybelAngel identifies as "a well-worn pressure technique rather than a position anyone should take at face value," designed to recast extortion as accountability journalism2.
  • Sophistication: High in social engineering and knowledge of EU legal process (correct, specific invocation of the European Investigation Order; correct impersonation of the actual Italian cybercrime unit). Unestablished in technical intrusion — the RAT narrative is self-reported and independently disputed by a firm with direct log visibility5.
  • OpSec / credibility signals: The group's own account has already required one public correction (disowning the $780M figure) and produces victim-name claims that conflict across the outlets it has spoken to — Georges Mikautadze in one, Alexander Shevchenko in another177 — which is itself evidence about how much weight its uncorroborated claims should carry.
  • Scale claims (unverified): A six-month operation and 147GB of Italian law-enforcement material, including "internal documents, calendars and personal material," among it "chat logs of a federal officer arguing with his wife"16104. None of this has been confirmed by any government source.

MITRE ATT&CK (IDs checked live on attack.mitre.org, 17 September 2026):

ID Technique Basis
T1586.002 Compromise Accounts: Email Accounts Control of, or access to, the Prefettura di Reggio Calabria's PEC mailbox — mechanism unconfirmed345
T1598 Phishing for Information Fraudulent data requests designed to elicit customer records under false authority114
T1199 Trusted Relationship Abuse of the lawful-request channel Revolut maintains for genuine government agencies2
T1657 Financial Theft Extortion demand tied to the stolen data89

No technique for the "spray and pray" blockchain-deposit-address matching mechanism is mapped here: it is a request made of Revolut, not an intrusion technique against a system, and forcing it into an Enterprise ATT&CK technique it doesn't fit would misrepresent what the framework covers.

Technical Indicators

# No malware, network infrastructure, or file hashes have been independently
# confirmed by Revolut, Italian authorities, or any named security firm.
# Hudson Rock's credential-count figure and Duel's mechanism description are
# the two pieces of independently-sourced technical detail available; both
# are noted here as reported, not as confirmed forensic findings.
email_addresses:
  - "entilocali.prefrc[at]pec.interno.it"   # impersonated/compromised PEC mailbox, Prefettura di Reggio Calabria [9][11]
  - "[undisclosed second pec.interno.it address, CC'd on the fraudulent request — identity and compromise status unconfirmed]"   # [19]
impersonated_entity:
  - "Polizia Postale e delle Comunicazioni (Italy's postal & cybercrime police)"   # [9]
legal_instruments_invoked_fraudulently:
  - "Purported Milan public prosecutor investigation (unconfirmed as genuine)"   # [9]
  - "European Investigation Order (EU Directive 2014/41 — a real mechanism, invoked fraudulently)"   # [9][19]
attacker-reported_infrastructure:
  - "Telegram channel used for initial leak, 13 Sep 2026 (suspended since)"   # [6]
  - "Dedicated extortion site under the name 'iamnotavillain' (ultimatum posted 16 Sep 2026)"   # [8][9]
credential_intelligence:
  - note: "Hudson Rock reports 300+ credential sets tied to pec.interno.it already circulating in infostealer logs, predating this incident's public disclosure"   # [20]
network_iocs: none disclosed
file_hashes: none disclosed
malware_family: unconfirmed (attacker claims an unnamed RAT; Hudson Rock disputes direct infection)   # [18][20]

Italy. The Procura della Repubblica di Reggio Calabria opened a criminal investigation into unauthorised access to a computer system and computer fraud1916. The Direzione nazionale antimafia e antiterrorismo has been briefed16. The Garante per la protezione dei dati personali launched checks on data-access and identity-verification procedures at Italian banks generally, not Revolut alone21. The Bank of Italy and the Agenzia per la Cybersicurezza Nazionale confirmed involvement alongside the Polizia Postale, with investigators explicitly trying to establish whether the government mailbox was spoofed or genuinely breached — officials describe a genuine breach as "a much more serious case" than spoofing15. Revolut states it serves roughly 5 million customers in Italy15.

United Kingdom. The ICO confirmed it "received a report and are assessing the information provided" — language CybelAngel's analysis notes has been "upgraded" by headline writers to "investigation" or "probe," neither of which the ICO's own statement supports26. The FCA stated it is "aware of the reported incident involving Revolut and are engaging with the firm to understand the impact and the steps being taken to address any potential harm"6. Under UK GDPR, organisations must generally notify the regulator within 72 hours of becoming aware of a reportable breach and inform affected individuals without undue delay where risk is high; CybelAngel's analysis states Revolut appears to have met both2.

European Union / Lithuania. Revolut's EEA banking business runs through Revolut Bank UAB, licensed in Lithuania and supervised jointly by the European Central Bank and the Bank of Lithuania, with Lithuania's State Data Protection Inspectorate (VDAI) acting as lead supervisory authority for cross-border GDPR matters — the same authority that investigated Revolut's 2022 breach1112. No public statement from the ECB, Bank of Lithuania, or VDAI on this specific 2026 incident was located as of 17 September.

United States. Not a party to this incident directly, but contextually relevant: Revolut received conditional OCC approval for a US national bank charter on 3 September 2026, eight days before this breach became public — a regulatory milestone CybelAngel's analysis notes would make any ransom payment "a significant regulatory event in its own right, with its own disclosure consequences"218.

Consumer advocacy. Codacons, an Italian consumer-rights group, has asked authorities to "accertare le dimensioni del fenomeno" — determine the true scale of the exposure19.

Revolut's own position. Core systems, databases and customer funds were not breached; the company frames the incident as "a sophisticated external fraud based on impersonation" rather than an intrusion into its own infrastructure — a position that is accurate on the intrusion question and separate from the personal-data-breach question, which both Revolut's own self-reporting and applicable law treat as distinct14215.

Impact Assessment

  • Customers affected: Reported, ~680 (FT, independently repeated); Revolut says only "limited"12915.
  • Countries represented: Reported, 31, per the attacker's own list as relayed by International Cyber Digest and Cybernews — Cyprus, Portugal, Germany, Spain, Bulgaria, Czechia, Romania, Poland, Malta, Norway, Sweden, Italy, Greece, Netherlands, Latvia, Austria, Belgium, Estonia, Croatia, Ireland, Slovakia, Finland, Lithuania, Hungary, Denmark, Turkey, Monaco, Luxembourg, Bahamas, Slovenia, United Kingdom, with the plurality reportedly from Switzerland and France17. This list is attacker-sourced and unconfirmed by Revolut or any government.
  • Data categories confirmed by Revolut: Full name, date of birth, occupation, postal/email address, phone number, passport/driving-licence copy, verification selfie image (the derived biometric matching template was not disclosed, per Revolut), account statements including IBANs, account-opening dates, withdrawal records, and complete transaction history including Bitcoin activity142.
  • Systems/funds compromised: Confirmed none, per Revolut1415.
  • Where the target list originated: Unknown. CybelAngel's analysis states this explicitly and flags it as unaddressed by Revolut or anyone else; 680 "should be treated as a floor on what the attacker knew rather than a ceiling"2.
  • Data publicly leaked to date: Reported, via Telegram since 13 September and the "iamnotavillain" site since 16 September; total volume (147GB claim) applies only to the separate, unverified Italian law-enforcement claim, not the Revolut customer data2104.
  • Financial loss / ransom paid: Unknown; no ransom confirmed paid, no funds confirmed touched85.
  • Scope of the mailbox compromise — isolated or broader: Unknown. Italian investigators are explicitly examining "se il caso rappresenti un episodio isolato oppure se la stessa tecnica sia stata utilizzata per colpire altri istituti finanziari" — whether the same technique hit other financial institutions16. The second, uninvestigated CC'd PEC address adds a second open thread4.
  • Detection-to-disclosure gap: Unknown and explicitly flagged as the single most important unpublished number in the incident by CybelAngel's analysis: the interval between the data leaving Revolut and Revolut learning that it had2.

Lessons and Defensive Recommendations

For SOC, legal and compliance teams at any regulated company

  • Domain authentication (SPF/DKIM/DMARC) answers exactly one question — did this message originate from the claimed domain — and nothing about whether its sender is entitled to make the request. As CybelAngel's analysis frames it: "Cannot answer: is the person at the keyboard entitled to demand this data?"2. Build a mandatory out-of-band callback, to a publicly listed number independent of anything in the inbound message, into every urgent or emergency data-request path, with no exception for urgency — urgency is the attack, not a reason to skip the check.
  • Revolut's own verification step existed, was understood, and worked — it just ran after disclosure instead of before2. The fix is sequencing, not new technology.
  • Treat a cluster of unusual requests concentrated on high-value accounts as a detectable signal in its own right, and log and rate-limit legal-request fulfilment so that pattern is visible to someone, not just to the requester2.

On the market this exploited

  • The FBI warned as far back as November 2024 of a sharp rise in compromised police and government email credentials sold on criminal forums, bundled with forged legal paperwork, specifically to enable fraudulent emergency data requests22. Independent researchers (Abnormal, Help Net Security, Dataminr, per CybelAngel's compilation) have since documented tiered, openly advertised pricing: an active .gov/.police mailbox from $40; a fully packaged fraudulent EDR "as a service" from ~$100 with turnaround claimed in 30 minutes; a verified US police department account around $1,000; higher-tier EU accounts priced at a premium specifically because major platforms respond to them faster; and access to the Kodex vetting portal itself, built to screen these requests out, going for around $2,0002. This is not an emerging technique. It is a priced, segmented market that has existed for years, and Revolut is simply the highest-profile customer of it to date.

For platform and legal/compliance teams specifically

  • Maintain an internally-owned, independently verified directory of contacts for law-enforcement and government agencies likely to send requests — never trust a callback number supplied in the request itself.
  • An inventory of every third party currently holding copies of your customers' identity documents matters here too: your exposure is not limited to what you hold2.

For government agencies operating certified-mail systems

  • A PEC-equivalent address is trusted precisely because recipients don't question it — which makes the mailbox itself, not just its usual traffic, the thing worth protecting with MFA and monitoring proportionate to that trust, not to how sensitive its typical content looks24.
  • The second, still-uninvestigated CC'd mailbox in this case is a reminder that a fraudulent request rarely announces its full blast radius; assume more than one account may be involved until logs say otherwise4.

For researchers and readers of this kind of story

  • Separate what the attacker says from what anyone has confirmed, all the way down to individual details. The ransom figure, the compromise method, the operation's duration, and even the names of alleged victims have all shifted or conflicted across outlets covering the same underlying claims — a pattern, not a one-off sourcing slip10177.
  • A company's "we were not hacked" and "we suffered a reportable data breach" are not in tension. Both were true here, simultaneously2.

Sources

Footnotes

  1. Revolut confirms customer data breach through fake government requests — TechCrunch, Jagmeet Singh, 12 September 2026 2 3 4 5

  2. Revolut gave away its customers' passports. Five days later, what do we actually know? — CybelAngel, Orlaith Traynor, 16 September 2026 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37

  3. La truffa a Revolut è stata fatta con un indirizzo della prefettura di Reggio Calabria — Il Post, 16 September 2026 2 3 4 5 6

  4. Revolut Data Leak May Trace Back to Compromised Italian Government Accounts — Security Affairs, Pierluigi Paganini, 16 September 2026 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21

  5. Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom — SecurityWeek, Ionut Arghire, 17 September 2026 2 3 4 5 6 7 8 9 10 11 12

  6. Revolut Data Breach Hits 680 Customers, UK Opens Probe as Hackers Demand 10,000 Bitcoin — CryptoTimes, 15 September 2026 2 3 4 5 6 7 8

  7. Revolut Keeps Getting Breached. The Fines Were Never the Problem. — Finextra (community/opinion), Igor Kostyuchenok, 15 September 2026 2 3 4 5 6 7

  8. Revolut Hackers Issue $3 Million Ransom for Customer Data — PYMNTS, 17 September 2026 2 3 4 5 6 7 8

  9. Revolut hack: criminals steal data of 700 European clients, demand $3m ransom — Euronews, 17 September 2026 2 3 4 5 6 7 8

  10. Crypto Industry Figures Blackmailed by Revolut's Hacker — GovInfoSecurity, 16 September 2026 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16

  11. Lithuanian Watchdog Launches Probe Into Revolut Data Breach — PYMNTS, 2022 2 3

  12. Digital Bank Revolut Confirms Customer Data Breach — BankInfoSecurity, 2022 2 3

  13. Revolut Faces $20 Million Loss as Attackers Exploit Payment System Weakness — The Hacker News, July 2023 2

  14. Revolut discloses data breach exposing financial info, passports — BleepingComputer, Sergiu Gatlan, 14 September 2026 2 3 4 5 6

  15. Revolut, truffa degli hacker con la pec italiana: consegnati dati di 700 clienti. Verifiche di Polizia postale, Acn, Bankitalia — MilanoFinanza, 15 September 2026 2 3 4 5 6 7

  16. Revolut, indagine a Reggio Calabria dopo la violazione della Pec della Prefettura — Il Reggino, 16 September 2026 2 3 4 5 6

  17. International Cyber Digest, thread on X/Twitter — @IntCyberDigest, 14–15 September 2026 2 3 4 5 6

  18. Revolut Obtains Conditional OCC Approval For US National Bank Charter — Crowdfund Insider, 3–4 September 2026 2

  19. Pec italiana compromessa, Revolut consegna i dati dei clienti agli hacker — ANSA, 15 September 2026 2 3 4 5 6 7

  20. Revolut gave customer IDs and financial data to a government impostor — Malwarebytes, Pieter Arntz, 14 September 2026 2

  21. Caso Revolut, dopo la truffa con la pec della prefettura di Reggio Calabria il Garante Privacy avvia verifiche sulle banche italiane — Gazzetta del Sud, 16 September 2026 2

  22. FBI: Spike in Hacked Police Emails, Fake Subpoenas — Krebs on Security, 4 November 2024

Topics: #revolut#emergency-data-request#italy#prefettura-reggio-calabria#impersonation#extortion#fca#ico#gdpr#infostealer#hudson-rock#fintech
Original Incident Report →

Related Research

FulcrumSec took 8.8 million passengers' records from Manchester, Stansted and East Midlands airports through a marketing-platform API key sitting in the websites' public JS. Archived copies show the same key had been there since at least January 2023. MAG refused the ransom; 550 GB was published.

Data BreachExtortion & Blackmail

A financially motivated threat actor (UNC5537) compromised Snowflake customer instances across 165+ organizations by credential stuffing against accounts lacking MFA, exfiltrating terabytes of sensitive data, and conducting mass extortion — the largest cloud data warehouse compromise to date.

Data BreachExtortion & Blackmail

Cl0p exploited an unauthenticated deserialization flaw in PTC Windchill as a zero-day in June 2026, deployed a purpose-built web shell that decrypts the application's keystore, and named 43 manufacturers, including Shell, Philips and GE. It was the second such flaw in three months.

Extortion & BlackmailOT & Industrial SystemsData Breach