Attackers posing as Italy’s interior ministry obtained Revolut customer data for five months, using a genuine address on PEC, the Italian government’s certified email system, to send the bank requests that looked entirely legitimate. On September 16, 2026, they publicly demanded $3 million not to release the files.
Revolut confirmed a “sophisticated external impersonation scam”
Revolut confirmed the incident on September 12, 2026, calling it a “sophisticated external impersonation scam” in which an unauthorized third party used a legitimate government agency’s email domain to submit fraudulent requests for information. The bank said “Revolut systems and customer funds are unaffected,” and that it had alerted the government agency concerned, law enforcement, data protection authorities, and its regulators.
The requests went to Revolut Bank UAB, the group’s Lithuanian entity, over roughly five months. The targets were not chosen at random. The attacker, who goes by the alias IAmNotAVillain, says they were found through blockchain analysis that looked for large holders of crypto assets.
The victims live in 33 countries, mostly Switzerland and France, with others in the UK, Germany, and Spain. The exposed data goes well beyond names and addresses: dates of birth, postal addresses and phone numbers, copies of passports and driver’s licenses, identity verification selfies, account statements, and transaction histories.
The attackers set a 24-hour ransom deadline
On the afternoon of September 16, the attackers demanded $3 million, about €2.6 million, payable in monero within 24 hours, or they would sell the files. “Revolut has not received any direct contact or demand from the individuals or group making these claims,” the bank said, adding that it is working with law enforcement and regulators. The same group also claims to have stolen data from Italian police services, a claim that has not been verified.
Answering the authorities is a data channel every bank runs
A European bank receives police and administrative requests every week. It must answer quickly, sometimes against a deadline, and without telling the customer. That duty to cooperate creates a legitimate, low-visibility path for data to leave the bank, and it is rarely subject to the same controls as employee access to customer files.
- The sender is authenticated by an email domain, and that domain can be compromised by infostealer malware.
- Legitimacy is often judged on how the document looks, not by calling the issuing authority back through an independent channel.
- The volume of requests pushes banks to industrialize processing, and so toward automated responses.
- The response contains exactly what an attacker wants: a verified identity, contact details, and financial history.
The victims now face identity fraud and targeted scams
To a fraudster, a complete onboarding file is worth far more than a card number. It can be used to pass identity checks elsewhere, open an account in the victim’s name, or make a call from the bank’s supposed security team sound convincing. The victims are also now known to hold digital assets, which makes them targets for social engineering fraud.
The case shifts the payment security question onto administrative ground. Security spending usually goes to customer authentication and transaction fraud detection. Here the data left through a door the law requires banks to keep open, unlocked by a valid address, and no one had to break into a customer account.