Skip to main content
LiMP VPN
All news

Revolut Hit by $3M Ransom Demand After 680 Clients' Data Stolen

Revolut Hit by $3M Ransom Demand After 680 Clients' Data Stolen

In short: On 16–17 September 2026 the hacking group iamnotavillain publicly demanded 6,000 XMR (roughly $3 million) from Revolut, threatening to sell the personal documents of around 680 European customers if payment was not made within 24 hours. The data — passports, driving licences and identity photos used for KYC verification — was obtained by compromising an Italian government email account and impersonating law enforcement. Revolut confirms its systems and customer funds are unaffected. This is a textbook trust-chain attack: the attackers did not breach Revolut directly — they compromised a third party Revolut was legally obliged to trust.

What happened

On September 16–17, 2026, iamnotavillain posted a public ultimatum on its dark-web site: unless Revolut transferred 6,000 Monero (XMR) — approximately $2.9 million at the time of the demand — within 24 hours, the group would sell the stolen data to other criminal organisations. A countdown timer ran alongside the message. Going public immediately, rather than opening private negotiations, is unusual in extortion operations; it signals an intent to generate maximum pressure and media coverage.

Revolut stated it had not received any direct contact or demand from the group, confirmed its systems remain secure and customer funds are intact, and said it has notified law enforcement and regulators, including the Bank of Lithuania where the company is incorporated.

How the attackers obtained data without breaching Revolut

The most striking aspect: Revolut's own infrastructure appears to have been uninvolved. According to Italian investigators, the attackers compromised an institutional email account belonging to a government body in the Reggio Calabria prefecture. Posing as law-enforcement officers, they used that address to submit official data-disclosure requests to Revolut over a period of several months.

From a compliance standpoint, those requests looked entirely legitimate. The result: KYC identification records for roughly 680 customers — passports, driving licences, identity cards and verification photographs. The group claims the total haul amounts to 147 gigabytes. Investigators note that targets were specifically selected "crypto whales" — customers with large cryptocurrency holdings — indicating a careful reconnaissance phase before the first request was even sent.

Why this matters beyond Revolut

This incident illustrates a trust-chain attack: rather than breaching the primary target, the attackers compromised a third party that the target was legally obliged to trust. The same vector drives many of the largest data exposures in recent years. No matter how hardened Revolut's own infrastructure is, the chain of trust it must extend to government institutions created an exploitable gap.

For individual users the implication is sobering. Even when a service you rely on has not been directly breached, your records can surface through a chain of forged official requests. KYC documents are a particularly high-value target because copies are held by every regulated financial service — banks, crypto exchanges, payment wallets. We covered a similar cascade in the Accenture source-code breach of 2026. For the broader picture on data-leak trends, see our privacy blog.

Regulatory response and investigation

Prosecutors in Reggio Calabria have opened an inquiry. The National Anti-Mafia and Counter-Terrorism Directorate (DNA) is involved, reflecting the assessed seriousness of the operation. Italy's data protection authority (Garante) has immediately launched security checks at Italian banks and contacted the Lithuanian supervisory authority due to Revolut's European headquarters there.

It remains unclear whether the attackers directly compromised the prefecture's mail server, exploited a broader Italian Interior Ministry system, or used email-spoofing to clone official addresses. Any of those scenarios points to a sophisticated, months-long preparation phase before the campaign began.

How to protect your data

Limit copies of your documents. Share identity documents only with services legally required to hold them. The fewer places that store a scan of your passport, the fewer attack surface points exist.

Enable account-activity notifications. Revolut and most fintech apps offer real-time push alerts for account actions. Turn them on and treat any request you did not initiate as suspicious.

Use a dedicated email address for financial services. This isolates the blast radius if that address is exposed: attackers who know only your "finance" email cannot automatically pivot to your other accounts.

Encrypt your connection when handling sensitive accounts. The Revolut attack exploited a government email, not intercepted traffic — but everyday users still face network-level risks. When opening banking or crypto apps on untrusted Wi-Fi, an encrypted tunnel makes your session unreadable to anyone else on the network. LiMP VPN is a no-logs service for iOS and Android; see plans for details.

Sources

Revolut Hit by $3M Ransom Demand After 680 Clients' Data Stolen