Revolut, the British digital bank that has grown into one of Europe's most valuable financial technology companies, confirmed on September 16, 2026 that an impersonation attack had led its compliance team to hand over confidential records belonging to roughly 680 customers. The fraudsters never breached the bank's own systems. Instead, they used a legitimate Italian government email domain to submit what looked like an authentic official request for information, and Revolut complied.
The channel at the centre of the case is Italy's PEC system, short for posta elettronica certificata, a legally recognised form of certified email that carries the same standing as a registered letter. Security Affairs reported on September 16, 2026 that the mailbox involved was allegedly associated with the Prefecture of Reggio Calabria and used the pec.interno.it domain, and that the people behind the requests posed as officers of the Italian Postal Police. A second institutional PEC address was reportedly copied in on the messages, a detail that would have made the request look more credible to a compliance officer working quickly.
According to an email sent to affected customers and viewed by AFP, the exposed material included addresses, verification photographs, identity documents, information about banking activity and Bitcoin holdings. Later reporting described passport and driving licence copies, contact details, IBANs, account statements, withdrawal records and full Bitcoin transaction histories. The victims were not a random slice of the customer base. Reporting indicates the targets were clients holding large volumes of crypto assets, with most of the 680 accounts sitting in France and Switzerland.
Revolut said it identified a sophisticated external impersonation scam and that, on detection, it immediately blocked the address and alerted the relevant government agency, enforcement agencies, data protection and financial regulators. The company said its systems and customer funds were unaffected and that it had contacted the limited number of impacted individuals directly. Founded in 2015, Revolut has 80 million customers globally and reached a valuation of US$115bn in a July secondary share sale. It secured a UK banking licence in March, conditional approval for a US licence this month, and filed for a Swiss licence on September 15, 2026.
Key Facts
Regulators in Britain and Italy are now involved. Britain's data protection regulator, the ICO, confirmed to AFP that it had received a report regarding the breach and was assessing the information provided. Italy's data protection authority asked all Italian banks to review their data access systems and report vulnerabilities, while Italian police opened an investigation. Crypto Times reported on September 17, 2026 that the Financial Conduct Authority said it was engaging with the firm.
The known scale is modest in customer terms and serious in data terms. AFP reported on September 17, 2026 that about 680 Revolut customers across several European countries were affected. Crypto Times reported on September 15, 2026 that the 680 total includes 12 customers in Ireland, 25 in Spain and 27 in Romania. Most of the accounts are in Switzerland and France, with the rest spread across 31 other mainly European countries including the UK, Germany and Spain, according to the threat actor's messages to the Financial Times. Those country shares have not been independently confirmed by Revolut.
The method was blunt rather than surgical. Korra, a researcher at Duel, described the operation as a spray and pray strategy: the attackers submitted large numbers of transaction identifiers and blockchain deposit addresses believed to belong to high value Revolut accounts and used fraudulent European Investigation Orders to request customer information, and the bank complied. Security Affairs reported on September 16, 2026 that the attackers sent transaction identifiers and blockchain deposit addresses and asked Revolut to link those transactions to specific customers.
Then came the extortion. A threat actor operating under the handle IAmNotAVillain claimed responsibility and demanded payment, initially reported as 10,000 Bitcoin, worth roughly US$780 million at mid September prices. Crypto Times reported on September 17, 2026 that the figure was later cut to about US$3 million, reported as 6,000 XMR, payable within 24 hours, with the confidential records of hundreds of customers to be sold to other criminal groups otherwise. The switch to Monero, a privacy focused cryptocurrency built to obscure sender, receiver and amount, was a deliberate move to defeat blockchain tracing. The actor's clearnet site appeared earlier, was taken down, and was then restored on a replacement domain with a countdown timer.
Not everything in circulation is confirmed. A person familiar with the matter told the Financial Times that Revolut had not been contacted by the perpetrators and had yet to receive a ransom demand through a negotiated channel. The actor also claims to have held access for approximately six months to systems belonging to several Italian law enforcement departments and to have exfiltrated approximately 147 GB of data including internal documents, emails, calendars and personal information. Neither claim has been independently verified. Revolut first notified affected customers on September 12, 2026, while the impersonation emails are said to have run for months before that date.
Analysis
The bigger picture here is that this was not a hacking story in the conventional sense. No firewall failed and no customer password was cracked. A bank was talked into releasing highly sensitive records by an email that looked official, arrived through a nationally trusted certified mail system, carried correct institutional formatting, cited law enforcement authority and came with a copied second government address for good measure. The attack worked on human process, not on code.
What made the target attractive is the same thing that makes the fallout dangerous. The actor told the Financial Times that accounts were picked through on chain analysis of Revolut customers with significant crypto holdings, a selection process that turns a public blockchain into a targeting list. French entrepreneur Mark Karpeles, the former Mt. Gox head, said he contacted police in Japan, where he lives, and checked into a hotel with his family as a precaution, citing kidnappings of crypto entrepreneurs in France. That reaction captures the shift from data loss to personal safety risk.
Evidence discipline matters here. Only the underlying disclosure is a company confirmed fact. The 10,000 Bitcoin demand and the US$3 million demand remain threat actor speech, as do the claims of 147 GB of stolen Italian files and six months of access. Investigators still need to establish where the alleged data originated and whether the Revolut operation was an isolated abuse of a government mailbox or part of a longer intrusion into Italian institutional networks.
Why It Matters
For the 680 people involved, the arithmetic is brutal. A customer base of more than 80 million makes the affected group statistically tiny, but the exposed set is unusually potent: identity documents, selfies, addresses, bank account details and full Bitcoin transaction histories. That combination supports identity fraud, account takeover and, in the worst case, physical coercion, which is precisely why crypto holders were chosen.
The regulatory and commercial timing adds pressure. The ICO is assessing the report, Italian police have opened an investigation, and the FCA is engaging with the firm. Revolut has just secured a UK banking licence in March, conditional approval for a US licence this month and a Swiss licence filing on September 15, 2026, all of which make supervisory confidence a strategic asset. A breach that exposes how a bank validates official demands is a governance question as much as a security one.
Next Up
The immediate test is whether the stolen records surface for sale, whether any ransom is negotiated or paid, and what the ICO concludes after its assessment. Italian investigators at the Polizia Postale, working alongside the country's data protection authority, will determine whether the Reggio Calabria mailbox was abused in isolation or whether, as the actor claims, wider government systems were compromised.
Banks across Italy and beyond are already being pushed to review how they grant access to customer records, and the practical lesson is out of band verification: an institutional email address, even a certified one, should not on its own authorise the release of identity documents. Expect that lesson to be written into supervisory guidance before the year is out.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.