How the Revolut data breach happened

Reqport, 25 September 2026. Based on information public as of this date. The investigation is ongoing and details may change.
On 24 March 2026, Revolut's legal team replied to an email from an Italian government address. The request had been sent to the wrong heading, so Revolut explained how to fill it in correctly so that it could be processed.
According to emails later published by Italian media, that exchange was one of the first in a correspondence that ran for months. The sender was not an Italian official. By September, around 680 Revolut customers had had their passports, selfies and full transaction histories handed over, and a criminal group was demanding a ransom for them.
This page sets out what is confirmed, what is still only claimed, and what the case means for any company that answers government data requests.
In brief
- Revolut disclosed customer files for around 680 people in response to requests sent from a genuine Italian government email account.
- Italy's national cybersecurity agency has confirmed that the account, a certified email address at a regional office of the Italian interior ministry, was compromised.
- The requests passed every check Revolut describes, because those checks verify the domain and the document. Neither can verify the person using the mailbox.
- The extortion has since moved from Revolut to individual customers.
What is confirmed
By Revolut
Revolut began notifying affected customers on or around 11 September and confirmed the incident publicly on 12 September. Its notice says an unauthorised email account on a legitimate government agency domain submitted fraudulent requests for customer information. Because the messages carried valid domain authentication, they were fulfilled in the belief that they were genuine.
The notice lists the data that may have been disclosed:
- Names, dates of birth, occupations, postal and email addresses, and phone numbers
- Copies of passports and driving licences, and verification selfies
- IBANs, account statements, withdrawal records and full transaction histories, including bitcoin
Revolut says it blocked the address, informed the agency, law enforcement, data protection authorities and financial regulators, and contacted the customers affected. It says its own systems and customer funds were not affected.
By Italian authorities
On 18 September, answering a question in the Italian parliament, interior undersecretary Wanda Ferro set out the findings of Italy's national cybersecurity agency (ACN). Revolut confirmed the breach on 15 September, stating that it had provided the data of 680 customers, eight of them Italian, and reported the compromise of a certified email (PEC) address belonging to the interior ministry's regional office in Reggio Calabria, known in Italy as the prefecture. CSIRT Italia, the agency's incident response team, verified the compromise by analysing a sample of one of the emails the attackers used.
The public prosecutor's office in Reggio Calabria has opened an investigation into unauthorised access to a computer system of public interest. The national anti-mafia and anti-terrorism directorate is also involved, given that a government body was used.
By regulators
Revolut is engaging with the UK Financial Conduct Authority and with Lithuania's State Data Protection Inspectorate, which supervises Revolut's EU bank. The FCA has said it is looking into the steps being taken to address any harm.
The case, step by step
The timeline below combines confirmed facts with material that comes from the attacker, from researchers who have spoken with him, and from emails published by Italian media. Each entry says where it comes from. Revolut has not confirmed the attacker's account.
Before March 2026: the mailbox
The person claiming responsibility uses the name IAmNotAVillain. He says he obtained the login through an infostealer, a type of malware that copies saved passwords from an infected computer and sends them to its operator. The threat intelligence company Hudson Rock reported finding roughly 300 compromised logins for the interior ministry's PEC webmail in its data, which shows exposure on the domain but not which accounts were used here.
Once inside, he says, he added his own recovery address, monitored all incoming mail, and deleted any reply the real user was not meant to see. Italian investigators have not yet established whether the account was accessed with stolen credentials or cloned by other means.
The address, according to Il Post, was entilocali.prefrc@pec.interno.it, the regional office's department for local authorities.
The approach
According to the attacker, he first tried forged court orders on other companies. He then chose Revolut's Lithuanian bank, Revolut Bank UAB, rather than its Italian branch. The emails published by Il Post refer to an investigation by the Milan public prosecutor and to the European Investigation Order, the instrument EU member states use to request evidence from one another.
24 March: the correction
In an email published by Il Post, Revolut asks the sender to correct the heading of a request and explains how to complete it so that the data can be released.
Early May: the apology
In another published exchange, Revolut apologises for sending data late and says it has started an internal audit to check the status of the file. Screenshots shared by the attacker show about forty messages in the inbox, most of them sent on 4 and 5 May.
The method
The requests did not name individuals. According to the attacker and researchers who spoke with him, they listed hundreds of public cryptocurrency transaction identifiers and wallet addresses and asked Revolut to identify the account holders behind them. Each address that matched a Revolut account came back as a complete customer file. He describes the people behind them as high-value crypto holders.
He also says the files were sent as password-protected archives, with the password in a separate email to the same mailbox.
11 to 12 September: disclosure
Revolut notifies affected customers and confirms the incident publicly.
13 to 15 September: competing claims
A Telegram channel under a different name claims the breach and circulates a figure of 10,000 bitcoin. IAmNotAVillain publishes a statement saying that channel belongs to a former associate holding only a small sample of the data. He also claims to hold 147 GB of separate data from Italian law enforcement, which has not been verified.
16 September: the ransom
IAmNotAVillain publishes a demand for 6,000 Monero, about 3 million dollars, on his website next to a countdown, threatening to sell the data to other criminal groups. Revolut tells Reuters it has received no direct contact or demand and that there have been no negotiations. The same day, prosecutors in Reggio Calabria open their investigation.
18 September: official confirmation
The Italian government confirms the 680 customers, the eight Italians and the compromised ministry address in parliament.
23 September: the customers
After the demand to Revolut expired, the group opened a leak site on the Tor network and began demanding payment directly from the customers affected, according to Fanpage.it. Identity documents, selfies and banking details for about a dozen customers were published. The pages were reported and taken offline shortly afterwards.
What is still unknown
Several questions remain open. Investigators have not yet determined how the ministry account was taken over. It is not known whether any data has been sold, or whether other companies received requests from the same account. The attacker's claims about duration, method and additional data have not been independently confirmed. No regulator has reached a conclusion.
A separate incident has also been in the news this week. DriveWealth, the US broker that previously handled Revolut's US stock trading, reported a social engineering attack on its own network on 4 and 5 September that exposed historic customer records. It is unrelated to the fake government requests.
Why the checks passed
Companies that receive government data requests by email tend to verify them in the same way. They check that the sending domain is real, and they review the document. If both look right, they respond, usually under time pressure and usually from a shared mailbox.
The domain checks worked as designed. SPF, DKIM and DMARC exist to stop spoofed email, and these messages genuinely left the ministry's mail server. Italy's PEC system adds legal proof of delivery on top. None of these mechanisms records who was logged in, so a compromised mailbox passes all of them.
The document was a PDF with an official crest, a prosecutor's letterhead and a legal basis. There is no register where a company can confirm that a prosecutor's order exists, and a well-made template looks the same on screen as a real one.
So the two checks confirmed a real domain and a plausible document. Neither could establish who was asking. That gap is the one the requests passed through, and it exists at most companies that handle these requests by email.
What would have caught it
The full record is not yet public, so certainty is not available. What is clear is that the checks Revolut describes were aimed at the domain and the document, and that checks aimed at the requester would have caught this far earlier.
- One account asked about hundreds of people. A single mailbox asking one bank to identify the holders of hundreds of wallet addresses, in batches, over several months, falls far outside the pattern of a genuine investigation. In an inbox those requests are separate threads. Tied to the person sending them, they form one history that looks wrong early.
- The credentials may already have been exposed. Logins stolen by malware end up in data that commercial threat intelligence services collect and index, and government email accounts are openly advertised on criminal forums. Screening the requester's address and domain against that data before the first reply would have given an early warning.
- A phone call at the first request. Revolut found the fraud by contacting the agency independently. The same call before the first disclosure, to a number found separately from the email, would have ended it at the start. A production order, unlike an emergency request, can wait a day for that.
- Sensitive data on its own path. Identity documents, selfies and full transaction histories should not follow the same route as a name and address. A second reviewer or a fresh verification step for those categories limits the damage even when a request is accepted.
Who carries the consequences
The mailbox that failed belonged to a government. The company that answered carries the outcome.
Revolut is the name in the headlines, its customers are the ones being extorted, and it is Revolut that answers to regulators in the UK and Lithuania. That is the practical risk for any company holding customer data. Legal liability depends on whether the safeguards were proportionate, and no regulator has decided that yet. Reputational and financial damage does not wait for the decision.
What this means beyond Revolut
The method is not new. In 2022, Apple, Meta and Discord disclosed user data in response to forged emergency requests sent from compromised police accounts. In 2024, the FBI warned that criminals were buying government email credentials to send fraudulent subpoenas and emergency requests to companies.
Two things are new here. The target was a bank, so the data was a complete KYC file rather than a subscriber record. And the request used a cross-border judicial instrument, so it reached a regulated European bank through its ordinary legal channel.
How Reqport handles the same problem
Reqport is a platform where companies receive and answer government data requests. Officers from the police and other authorities send their requests through Reqport instead of by email, and every one of them is checked before the request reaches the company.
Checks at registration:
- Each authority is validated against official registers before its domain is admitted, and every domain is re-verified every 24 hours.
- Each officer registers individually and confirms access through their own agency mailbox.
- Every address, and the domain behind it, is screened against compromised-credential intelligence, the data that shows whether a login has been stolen and offered for sale.
Checks for as long as the account exists:
- Access is renewed daily through the agency mailbox, so an account cannot outlive the person and mailbox it belongs to.
- Credential screening runs continuously, so a login that leaks after registration is flagged before it is used.
- Device and behaviour anomalies, such as a login from unfamiliar hardware or activity that breaks from the officer's normal pattern, hold the account until it is confirmed.
- Every request is tied to the officer who sent it, so unusual behaviour from one account is visible immediately.
- An officer blocked at one company is blocked across the whole platform.
When any check raises a flag, the request is held and Reqport contacts the officer or the agency by phone, using a number found independently, before anything reaches the company.
The requests themselves are processed in a confidential computing environment. The data stays encrypted, and Reqport cannot read it.
Applied to the Revolut case, several of these checks would have come into play early. A ministry account appearing in stolen-credential data would have been flagged before its first request. An account operated from outside the agency would have shown up as a device anomaly. And hundreds of subjects requested by a single officer would have been visible on that officer's history, instead of spread across dozens of email threads.
Reqport does not verify the document attached to a request, and no platform can, since there is no register of prosecutors' orders to check it against. What Reqport verifies is the person sending it, and in this case that was the part that could have been checked.
If your team answers government data requests and you want to see how a request like this would look on Reqport, we are happy to walk you through it.
Sources
- Revolut customer notification, reported by BleepingComputer, September 2026. https://www.bleepingcomputer.com/news/security/revolut-discloses-data-breach-exposing-financial-info-passports/
- TechCrunch, 12 September 2026. https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/
- Help Net Security, 14 September 2026. https://www.helpnetsecurity.com/2026/09/14/revolut-data-breach-privacy/
- Il Post, 16 September 2026 (the ministry office's address, 24 March and May emails). https://www.ilpost.it/2026/09/16/mail-reggio-calabria-truffa-revolut/
- Sky TG24, 16 September 2026 (Reggio Calabria investigation). https://tg24.sky.it/cronaca/2026/09/16/revolut-truffa-pec-furto-dati-inchiesta-reggio-calabria
- Euronews, 17 September 2026 (ransom demand). https://www.euronews.com/2026/09/17/revolut-hack-criminals-steal-data-of-700-european-clients-demand-3m-ransom
- Irish Times, 17 September 2026 (ransom demand). https://www.irishtimes.com/business/2026/09/17/hackers-demand-revolut-hand-over-3m-ransom-amid-data-breach/
- SecurityWeek, September 2026 (five-month campaign, Revolut Bank UAB). https://www.securityweek.com/revolut-data-breach-5-months-680-high-profile-accounts-3m-ransom/
- IlDispaccio, 18 September 2026 (parliamentary answer, ACN and CSIRT Italia findings). https://ildispaccio.it/calabria/reggio-calabria/2026/09/18/revolut-violata-una-pec-della-prefettura-di-reggio-calabria-coinvolti-otto-clienti-italiani/
- InformaCalabria, September 2026 (breached or cloned account, anti-mafia directorate). https://www.informacalabria.it/truffa-revolut-pec-prefettura-di-reggio-calabria-riscatto/
- OCCRP, September 2026 (Revolut statement to Reuters, investigation status). https://www.occrp.org/en/news/hackers-demand-3m-ransom-in-revolut-data-leak
- MLex, 21 September 2026 (FCA and Lithuanian State Data Protection Inspectorate). https://www.mlex.com/mlex/data-privacy-security/articles/2527689/revolut-breach-on-desks-of-uk-finance-regulator-lithuanian-privacy-watchdog
- Fanpage.it, 23 September 2026, as reported by Pasquale Pillitteri (leak site and extortion of customers). https://pasqualepillitteri.it/en/news/17742/revolut-hackers-ransom-customers-leak-site
- Silere Non Possum, September 2026 (published correspondence). https://silerenonpossum.com/it/casella-viminale-caso-revolut-ministero-silenzio/
- Hudson Rock, 15 September 2026 (infostealer findings on the PEC domain). infostealers.com
- The Next Web, 24 September 2026 (DriveWealth incident). https://thenextweb.com/news/drivewealth-breach-revolut-customers-us-stocks
- Bloomberg, 30 March 2022 (forged emergency requests to Apple, Meta and Discord).
- FBI public service announcement, November 2024 (fraudulent emergency data requests).
What's happening between law enforcement and companies
Occasional analysis on new rules, cases and practice.

Reqport
Reqport is a platform for handling law enforcement and other authority data requests.
LinkedInRelated articles

The missing link to stop fraud
A fraudulent payment is often recoverable for a short time after it leaves the account, while the money is still in the regulated system. The key is acting fast.