Hackers claiming responsibility for a recent data breach at Revolut have disclosed that they obtained sensitive customer information by exploiting an Italian government email system and impersonating law enforcement authorities. The breach reportedly affected nearly 700 Revolut customer accounts, significantly more than initially acknowledged by the fintech company.
According to messages sent by the group using the pseudonym iamnotavillain, they first contacted Revolut several months ago via Italy’s La Posta Elettronica Certificata (PEC) system, a secure email network used by government entities for official communication. The hackers posed as Italian law enforcement officers and repeatedly requested confidential details, including addresses, phone numbers, and transaction records for specific clients, justifying these requests as necessary for official investigations. A source familiar with the matter confirmed that Revolut complied with the requests, engaging in email exchanges through the PEC system over an extended period.
The group claimed they identified their targets by conducting blockchain analysis to pinpoint Revolut accounts with substantial cryptocurrency holdings, referring to these accounts as belonging to "crypto whales." Most of the affected customers were from Switzerland and France, but the data also included residents from 31 other European countries, such as the United Kingdom, Germany, and Spain.
Revolut has maintained that its internal systems and databases were not breached, emphasizing that the incident involved fraudulent use of a legitimate state-regulated communication channel rather than a direct hack of its infrastructure. The company stated it is providing immediate support to those affected and cooperating closely with law enforcement and regulators.
Following the disclosure, the hackers issued a public ransom demand, threatening to sell the stolen data to other criminal groups unless Revolut pays $3 million (in Monero cryptocurrency) within 24 hours. This public ultimatum, accompanied by a digital countdown and published on a dedicated website, is uncharacteristic since ransomware demands typically occur privately. The hackers warned that failure to comply would result in the release and sale of the information and placed responsibility for any consequences on Revolut.
The stolen data reportedly includes sensitive customer documents such as driving licenses, passports, identity verification photos, and transaction histories. A short video released by the hackers showed someone navigating through purported Revolut customer files.
Revolut declined to comment on the ransom demand but reaffirmed its commitment to addressing the breach and assisting affected customers. Meanwhile, Italian authorities, including the postal police, state police, interior ministry, and cybersecurity agency, have confirmed ongoing investigations but have not provided further comment.
The full motivation and identity of the attackers remain unclear. Sources indicated that Revolut has yet to engage in direct negotiations with the hackers and has not received previous ransom requests. The incident has raised concerns among customers about the security of their personal information and the risks posed by sophisticated social engineering tactics exploiting official communication channels.
