- A data leak may have affected about 680 Revolut customers after attackers allegedly sent fraudulent requests from compromised Italian government email accounts.
- Researchers said the attackers used public cryptocurrency transactions and wallet addresses to seek KYC data on potentially wealthy customers.
- Revolut has not confirmed all published figures and details, including claims circulated by the alleged attackers.
Attackers used compromised Italian government email inboxes to send fraudulent official requests to Revolut, contributing to a leak that may have affected about 680 customers, the Financial Times and International Cyber Digest reported in September 2026. The reported attack targeted the channel financial institutions use to interact with government agencies rather than Revolut’s app, and lawyers and civil-rights advocates said it exposed a systemic weakness in verifying official requests.
International Cyber Digest said people claiming responsibility told it that the operation targeting Revolut ran for six months and that they had also compromised several Italian law-enforcement departments. Revolut has not confirmed all figures and details published by researchers or the alleged attackers.
Max Karpis, an early Revolut investor and independent analyst, said the company had received ransom demands and that people claiming to possess the stolen files were posting customer identity documents and selfies on Telegram. Karpis cautioned that Revolut had not confirmed a circulating claim involving 10,000 BTC and said the company continued to describe the incident as limited, with neither its app nor customer funds hacked.
Researchers describe fraudulent data requests
An X user operating under the name Korra reported, citing Duel, that an attacker using the alias IAmNotAVillain employed a “spray and pray” strategy. The attacker allegedly sent Revolut hundreds of cryptocurrency transaction IDs and deposit addresses while requesting details about the associated accounts.
Duel said the requests were presented as a forged European Investigation Order and that Revolut allegedly responded with archives containing customer data. Researchers said they obtained and verified authentic copies of emails in .eml format. One email contained 10 folders, each corresponding to a separate customer, with identity-document photographs, verification selfies, account information and unredacted transaction data, according to Duel. The password for the encrypted ZIP archive was reportedly sent in a separate email.
Researchers said the method could have allowed the attacker to target wealthy customers because public blockchains display addresses and transactions. A cryptocurrency transaction could therefore serve as a search key in a request to a centralized financial institution. They alleged that the attacker submitted hundreds of transaction hashes and deposit addresses believed to be associated with high-asset customers and that Revolut returned information about the corresponding users.
Researchers and people claiming contact with the attackers have separately circulated allegations that 147 GB of data was stolen from Italian government systems. Those sources have also made claims about the publication of customer data, but Revolut has not confirmed all those details.
Documents indicate jurisdictional refusal
Lyudmyla Kozlovska, a human-rights advocate and president of the Open Dialogue Foundation, said documents showed that Revolut refused on July 24, 2026, to disclose information directly in response to a request covering 198 hashes. She said 169 were linked to Revolut Ltd in the United Kingdom and 29 to its Swiss legal entity.
According to Kozlovska, Revolut invoked a jurisdictional limitation because the request covered only accounts at Revolut Bank UAB in Lithuania. In other cases, the requester was directed to use the British mutual legal-assistance procedure.
Kozlovska said European anti-money-laundering rules impose no separate obligation on a bank to verify the true party behind an authenticated government request. “EU AML law imposes no verification duty on the bank and provides no meaningful mechanism to check who is really behind an authenticated state request. Refusal to answer carries fines in the millions,” she said.
Security advice and policy concerns
Karpis advised potentially affected customers to freeze credit lines where possible, set a new app passcode, enable card-transaction alerts and avoid engaging with people who already know their IBAN or previous cryptocurrency transactions. He also suggested considering passport replacement where local rules allow a compromised document number to be canceled, and warned that offers to “delete the file” for payment could be another extortion attempt.
Kozlovska urged European citizens to ask members of the European Parliament for urgent hearings on the use of mass financial-data collection as an attack tool. She said similar risks could affect banks, cryptocurrency exchanges and payment services in jurisdictions governed by Financial Action Task Force rules and related anti-money-laundering laws.
She said human-rights organizations, victims and experts, with support from the Open Dialogue Foundation, had raised the issue before the European Parliament. Kozlovska added that a European Parliament resolution dated June 18, 2026, separately identified the risk of transnational financial repression.
As of the source article’s publication, Revolut had not posted separate guidance on X for customers responding to the incident. The company recently received conditional approval to establish a national bank in the United States.
Source: Incrypted
