← Back to News
Fraud

Fake Italian police requests expose 680 Revolut customer files

For five months, attackers used a genuine address on Italy’s certified government email system to pull full customer files from Revolut, then demanded a $3M ransom. The weak point was the channel banks use to answer the police.

Attackers posing as Italy’s interior ministry obtained Revolut customer data for five months, using a genuine address on PEC, the Italian government’s certified email system, to send the bank requests that looked entirely legitimate. On September 16, 2026, they publicly demanded $3 million not to release the files.

⚠️
No system was hacked
None of Revolut’s systems was breached. The attackers hijacked the channel a bank uses to answer the authorities, with a real government address. Every European payment service provider answers these requests, and many treat them as routine paperwork.

Revolut confirmed a “sophisticated external impersonation scam”

Revolut confirmed the incident on September 12, 2026, calling it a “sophisticated external impersonation scam” in which an unauthorized third party used a legitimate government agency’s email domain to submit fraudulent requests for information. The bank said “Revolut systems and customer funds are unaffected,” and that it had alerted the government agency concerned, law enforcement, data protection authorities, and its regulators.

The requests went to Revolut Bank UAB, the group’s Lithuanian entity, over roughly five months. The targets were not chosen at random. The attacker, who goes by the alias IAmNotAVillain, says they were found through blockchain analysis that looked for large holders of crypto assets.

680
customer accounts targeted, approximately
SecurityWeek
5 months
period during which the fake requests were sent
SecurityWeek
33
countries affected, mostly in Europe
The Irish Times
$3M
ransom demanded, in monero
The Irish Times

The victims live in 33 countries, mostly Switzerland and France, with others in the UK, Germany, and Spain. The exposed data goes well beyond names and addresses: dates of birth, postal addresses and phone numbers, copies of passports and driver’s licenses, identity verification selfies, account statements, and transaction histories.

A person holding several passports
The documents collected at onboarding are the real prize. Unlike a password, they cannot be changed.

The attackers set a 24-hour ransom deadline

On the afternoon of September 16, the attackers demanded $3 million, about €2.6 million, payable in monero within 24 hours, or they would sell the files. “Revolut has not received any direct contact or demand from the individuals or group making these claims,” the bank said, adding that it is working with law enforcement and regulators. The same group also claims to have stolen data from Italian police services, a claim that has not been verified.

Answering the authorities is a data channel every bank runs

A European bank receives police and administrative requests every week. It must answer quickly, sometimes against a deadline, and without telling the customer. That duty to cooperate creates a legitimate, low-visibility path for data to leave the bank, and it is rarely subject to the same controls as employee access to customer files.

  • The sender is authenticated by an email domain, and that domain can be compromised by infostealer malware.
  • Legitimacy is often judged on how the document looks, not by calling the issuing authority back through an independent channel.
  • The volume of requests pushes banks to industrialize processing, and so toward automated responses.
  • The response contains exactly what an attacker wants: a verified identity, contact details, and financial history.
ℹ️
How to vet a law enforcement request
Call the issuing authority back on a number from the official directory, never the one on the request. Log every response as privileged access. Alert on patterns: one office querying dozens of high-balance accounts over a few months is not routine.

The victims now face identity fraud and targeted scams

To a fraudster, a complete onboarding file is worth far more than a card number. It can be used to pass identity checks elsewhere, open an account in the victim’s name, or make a call from the bank’s supposed security team sound convincing. The victims are also now known to hold digital assets, which makes them targets for social engineering fraud.

A hand holding a closed passport
With 33 countries affected, a leak like this cannot be undone. It can only be monitored, account by account.
Spring 2026
The fake requests begin
Requests sent from a genuine PEC address start reaching Revolut Bank UAB.
September 12, 2026
Revolut confirms
The bank describes an external impersonation using a legitimate government domain.
September 16, 2026
Ransom demand
$3 million in monero, within 24 hours.
September 17, 2026
Deadline passes
Revolut says it has received no direct demand and is cooperating with the authorities.

The case shifts the payment security question onto administrative ground. Security spending usually goes to customer authentication and transaction fraud detection. Here the data left through a door the law requires banks to keep open, unlocked by a valid address, and no one had to break into a customer account.

Provenance

Published September 17, 2026

5 sources, 4 distinct domains

↗ TechCrunch, Revolut confirms customer data breach through fake government requests · techcrunch.com↗ The Irish Times, Hackers say they breached Italian state email to target Revolut ‘crypto whales’ · irishtimes.com↗ The Irish Times, Hackers demand Revolut hand over $3m ransom amid data breach · irishtimes.com↗ SecurityWeek, Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom · securityweek.com↗ PYMNTS, Revolut Says Customer Data Leaked in Email Scam · pymnts.com
← All news