2026-09-13 · view entry permalink →
Revolut discloses a customer KYC data breach after fulfilling a fraudulent request sent from inside a genuine government agency's own email domain
Revolut confirmed to TechCrunch on 2026-09-12 that it disclosed sensitive customer data after receiving a fraudulent information request sent from "an unauthorised email account sent directly using the official government agency's email domain" (Revolut, via Security Affairs, 2026-09-12); Security Affairs assesses the attacker either registered a rogue mailbox within that domain or compromised an existing one. Because the message carried valid domain-authentication credentials, Revolut's compliance and KYC-response process treated it as authentic and fulfilled it: exposed data included full name, date of birth, occupation, postal and email address, phone number, passport or driver's-licence copies, verification selfies, IBAN and account statements, withdrawal records and full transaction history including Bitcoin (Security Affairs, 2026-09-12). "No systems were compromised, no malware was used"; the entire incident was a social-engineering compromise of the legal and regulatory data-request channel rather than a technical intrusion (Security Affairs, 2026-09-12). Revolut confirmed to TechCrunch that a "limited" number of customers were affected, declining to disclose the exact count, the government agency involved, or whether the incident was confined to one market (TechCrunch, 2026-09-12). Revolut discovered the fraud only after independently contacting the government agency to verify the request, at which point the agency confirmed it had not made it (Security Affairs, 2026-09-12); it has since blocked the sending mailbox and notified the agency, law enforcement and financial regulators (TechCrunch, 2026-09-12).
The same weakness applies to any organization whose legal or regulatory data-request process trusts that a request's sending domain is proof of the sender's authority: an attacker who obtains or spoofs access to a single mailbox on that domain can submit an urgent, seemingly authentic request that bypasses the normal verification a company would otherwise apply. Here that pattern reached a major fintech's KYC/AML compliance channel, and the entire compromise happened at the request-verification step: no phishing link was clicked and no credential was stolen, only an email that domain-authenticated correctly and asked for the right kind of data in a plausible way.
For any organization that operates a legal or regulatory data-request intake process, the transferable lesson is that domain-level email authentication (the same trust SPF, DKIM and DMARC exist to establish) is not proof of institutional authority: an adversary who controls, or convincingly spoofs, a single mailbox on a trusted government or law-enforcement domain can defraud any recipient who verifies a request only by checking that it came from the right domain. This cuts both ways for a public-sector authority: any authority that itself issues legal data requests to third parties (banks, telcos, cloud providers, ISPs) as part of investigations should assume that a compromise of its own mail infrastructure could be used to defraud those third parties in its name, and should expect the recipients of its own legitimate requests to apply out-of-band verification rather than treat that as an insult to its authority.
Revolut received a request for customer information that appeared to come from a legitimate government agency. The request came from an unauthorised email account sent directly using the official government agency's email domain.
As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request.
Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.
People claiming responsibility for the incident have posted samples of the allegedly stolen information across several Telegram groups and the material appears to include details belonging to prominent individuals, including business leaders, sports professionals and performing artists.
The attackers have threatened to publish additional information “every day” unless Revolut pays a ransom of 10,000 Bitcoin – currently worth more than $782m.
The hacker gained access to government employee accounts using an infostealer. After gaining entry to an employee's email, they would log in, add a recovery email under their control, begin logging activities, and silently monitor communications.
By checking Hudson Rock's extensive cybercrime database, we identified approximately 300 compromised pec.interno.it webmail logins stemming from already infected machines. Based on this intelligence, we assess that it is highly unlikely the hacker actively infected these specific employees themselves.
Upon receiving a reply to their fraudulent emails, they would immediately download it as a .eml file and delete it before the actual account owner noticed.
The data breach is understood to have affected at least 680 customer accounts.
"one of their former accomplices took only part of the obtained data. He is posing as the actual perpetrator. He is, however, a fraud." # (translated from German)
"'Imnotavillain' is now offering the data sets of 680 high-ranking individuals for sale. As a special twist, the perpetrators are also luring the individual data subjects; they could buy the removal of their own record before the data is sold as a whole to interested parties in the future." # (translated from German)
The quotation from Revolut's customer notification in the opening paragraph was rendered with an inserted ellipsis. Revolut's sentence reads in full: "The request came from an unauthorised email account sent directly using the official government agency's email domain" (Revolut, via Security Affairs, 2026-09-12). The two elided words are the operative ones for a defender reading this as a control failure: the request was sent directly from the agency's own domain rather than from a lookalike, which is why domain authentication passed and why the sending domain told Revolut's reviewer nothing about the sender's authority.
Parties claiming responsibility for the breach have posted samples of the allegedly stolen data across several Telegram groups, reported to include details belonging to "prominent individuals, including business leaders, sports professionals and performing artists," and are demanding Revolut pay a ransom of 10,000 Bitcoin, worth more than 782 million US dollars at the time of reporting, threatening to publish further data "every day" if unpaid (DataBreaches.net, relaying Computing.co.uk, 2026-09-15). This is the first extortion dimension reported on an incident this entry previously described only as a disclosed process-abuse breach with no stated attacker demand. Computing.co.uk, the outlet that originated this reporting, remains unreachable on every transport tried as of 2026-09-16; neither Revolut nor a second independent outlet has confirmed the ransom figure, the Telegram posting, or the claimed victim identities, so these remain attacker-stated claims rather than established fact.
Hudson Rock, relaying the attacker's own account to the Duel Investigations Team, reports the access vector claimed behind the fraudulent request: infostealer-compromised webmail accounts on pec.interno.it, the certified-email domain of Italy's Ministry of the Interior. Per that account, the hacker gained access to government employee accounts using an infostealer, and after gaining entry to an employee's email, would log in, add a recovery email under their control, begin logging activities, and silently monitor communications (The Duel Investigations Team, via Hudson Rock, 2026-09-15). Upon receiving a reply to their fraudulent emails, the operator would immediately download it as a .eml file and delete it before the actual account owner noticed, an anti-forensic technique the account says let the campaign run for roughly five months, beginning with forged court orders before pivoting to Revolut Bank UAB, Revolut's Lithuania-licensed EU subsidiary obligated to respond to European Investigation Orders (The Duel Investigations Team, via Hudson Rock, 2026-09-15). Hudson Rock's own cybercrime database independently identified approximately 300 compromised pec.interno.it webmail logins from already-infected machines, and on that basis assesses it is highly unlikely the hacker actively infected these specific employees themselves (Hudson Rock, 2026-09-15); the attacker's own account of the initial-access method was itself inconsistent, first describing a remote-access trojan and later an infostealer. This resolves the access-vector question the original disclosure left open; CyberInsider reports Revolut told it only that the fraudulent request "appeared authentic based on the technical indicators available to its staff" (CyberInsider, 2026-09-16), and Revolut itself has not confirmed the five-month timeline, the pec.interno.it detail, or the anti-forensic technique. CyberInsider separately references unnamed "separate reporting" giving a customer count of around 680, a figure this entry cannot independently verify.
The Irish Times independently confirms the customer count this entry previously could not verify: "The data breach is understood to have affected at least 680 customer accounts" (The Irish Times, 2026-09-17), reporting on a group spelling its name "iamnotavillain." A group whose name Heise Online spells "Imnotavillain" now claims sole responsibility for the breach on its own darknet site, disputing a rival claimant it says "took only part of the obtained data" and "is posing as the actual perpetrator" while calling that rival "a fraud" (Heise Online, 2026-09-25, translated from German); no cited source explicitly states the two spellings name the same actor, and neither claimant's identity is independently established. Having already issued a 6,000 XMR ($3 million) ransom ultimatum to Revolut itself with a 24-hour deadline, published on its own website with a countdown clock (The Irish Times, 2026-09-17); no cited source states what happened when that deadline passed, a separate, larger 10,000 Bitcoin demand this entry's 2026-09-16 update recorded came from a single, since-unreachable relay and is not corroborated by this Irish Times reporting or any other cited source, and the two figures are not reconciled here; a group under this name has now pivoted to individually extorting the roughly 680 named customers directly: it is "offering the data sets of 680 high-ranking individuals for sale" and letting each "buy the removal of their own record before the data is sold as a whole to interested parties in the future," publishing sample records including full name, email, phone number, address, account IDs, crypto withdrawal and balance data, bank transactions, and KYC documents and selfies as proof (Heise Online, 2026-09-25, translated from German). Revolut itself told the Irish Times at the time of the original ultimatum that it "has not received any direct contact or demand from the individuals or group making these claims" (The Irish Times, 2026-09-17); neither Revolut nor an independent researcher has confirmed either claimant's identity or the completeness of the data set.