An attacker impersonated Italian law enforcement using a stolen government email account. For roughly six months, Revolut complied with every request – and even coached the attacker on fixing their paperwork.
Revolut’s core systems were never breached. No firewall was bypassed, no zero-day exploit deployed. Instead, an extortionist armed with a compromised Italian government email address sent forged legal requests to Revolut’s compliance team in Lithuania – and the team fulfilled them, handing over 680 complete identity dossiers on high-net-worth customers.
The stolen data included high-resolution passport scans, biometric verification selfies, home addresses, phone numbers, IBAN details, and years of cryptocurrency transaction history. Targets were surgically chosen: crypto protocol founders, gambling executives, market makers, and professional athletes.
‼️ BREAKING: The threat actors who targeted Revolut with information-demand emails are now posting sensitive customer data, including that of high-profile clients such as tennis player Shevchenko and Römer, CEO of Gamdom/Skinscom.
They want Revolut to pay up. They say they’ll… pic.twitter.com/obuVOOABx7
— International Cyber Digest (@IntCyberDigest) September 13, 2026
How the Attack Worked
The operation began with a commodity infostealer – likely RedLine or Raccoon – used to compromise an administrative workstation inside the prefecture of Reggio Calabria in southern Italy. From that machine, the attacker extracted credentials for a certified government mailbox hosted on Italy’s Ministry of Interior infrastructure.
Italy’s Posta Elettronica Certificata (PEC) system gives messages between verified addresses the legal equivalence of registered mail. Because the stolen mailbox sat on a legitimate interno.it domain, every forged message passed SPF, DKIM, and DMARC authentication. The attacker used it to send fabricated European Investigation Orders demanding full KYC packages on specific targets.
Revolut’s compliance team, operating under its Lithuanian banking license, received these requests from an Italian municipal mailbox concerning citizens of France, Switzerland, Germany, and dozens of other nations. Rather than verifying the requests through independent judicial channels, the team complied.
Revolut Coached the Attacker
When the attacker’s initial forged documents contained obvious legal and formatting errors, Revolut’s compliance desk did not flag the anomalies. Instead, according to leaked email correspondence published by security research group, staff explained exactly why the submission couldn’t be processed, detailed the correct legal format required, and instructed the attacker on how to revise the paperwork. The attacker corrected their documents accordingly and Revolut released the data.
‼️ BREAKING: Our investigations team at Duel is in contact with the Revolut hacker, and we’ve found out a lot more about how he did what he did.
– The hacker got access to government employee accounts using an infostealer. After gaining access to an employee’s email, they would… pic.twitter.com/z0zoCGqDpA
— Korra (@korraflow) September 15, 2026
The attacker also employed a brute-force tactic: pulling hundreds of Bitcoin transaction hashes from public blockchains, bundling them into requests, and asking Revolut to identify the account holders behind each one. Revolut matched those transactions against internal records and returned the real-world identities, passport scans, and home addresses of the wallet owners.
‼️ BREAKING: Duel can report that the Revolut hacker used a “spray and pray” strategy, sending hundreds of cryptocurrency transaction IDs to Revolut and asking for the associated account details. Revolut complied.
This explains the sheer volume of data the hackers were able to… pic.twitter.com/RqGsuEIkMZ
— Korra (@korraflow) September 15, 2026
Two Months of Silence
Revolut did not notify affected customers until the evening of Friday 11 September 2026. But extortion was already well underway. Felix Römer, co-founder of crypto casino Gamdom, published evidence that blackmailers had contacted him on 16 July – two full months earlier – demanding $25,000 in Bitcoin via Telegram.
Revolut announced this 3 day ago
But already 2 months ago me and others started to get blackmailed with the compromised data
It was was only properly communicated once it fully became clear to the public that Revolut gave out all this sensitive data https://t.co/1578oBAzxw pic.twitter.com/zR3wTPEwJE
— Felix (@Romer) September 15, 2026
Marc Zeller, founder of the Aave Chan Initiative, and Mark Karpelès, former CEO of Mt. Gox, both confirmed receiving breach notifications. When on-chain investigator ZachXBT attempted to ask Revolut’s support channels about the scope of the leak, Revolut blocked him.
Woke up to all my data leaked by @Revolut.
Sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way. pic.twitter.com/RimOBQr7DW
— Marc Zeller (@mzeller) September 12, 2026
From the Revolut hacker posts, a msg.eml of almost 60MB, sent via Italy’s certified email system (PEC), with the password also sent by email “in the next email.”https://t.co/mhY06Ugeoj pic.twitter.com/ChtjMFHure
— Mark Karpelès (@MagicalTux) September 13, 2026
Idk why I am blocked by both Revolut accounts. pic.twitter.com/wLd3IdmSF9
— ZachXBT (@zachxbt) September 12, 2026
By 13 September, stolen files – passports, selfies, bank statements, tax certificates – were circulating on Telegram and public image boards. A dedicated extortion portal appeared at iamnotavillain.xyz, publishing a manifesto and threatening to release data in daily batches. The site listed 19 zip archives containing 688 documents, alongside a separate 147-gigabyte trove of files taken from Italian government servers during the same campaign.
‼️ BREAKING: We’re in contact with the Revolut hacker. According to them, they didn’t only take Revolut data, they’ve also compromised multiple Italian law enforcement departments.
They say the operation targeting Revolut ran for six months, and that they used Italian law… pic.twitter.com/ZYGWZEc0tL
— International Cyber Digest (@IntCyberDigest) September 14, 2026
On 15 September, domain registrar GoDaddy intervened following abuse complaints, placing the site on hold and taking it offline.

Nick Percoco, Chief Security Officer at Kraken, warned that when an attacker obtains a verified home address paired with years of cryptocurrency transaction history, the threat is no longer financial fraud – it becomes a blueprint for physical home invasion.
Regulatory Response
Lithuania’s State Data Protection Inspectorate has opened a formal GDPR investigation. The UK’s Information Commissioner’s Office has initiated inquiries – significant timing given Revolut’s ongoing pursuit of a full British banking license. On 16 September, Italian lawmakers submitted a parliamentary inquiry demanding answers on how the Reggio Calabria mailbox was compromised for months without detection.
After Revolut’s customer data leak, Italy is now asking how far this goes.
The files left Revolut after requests that arrived on a real Italian official channel. Revolut’s systems were not broken into. Revolut did not spot that the other end was not the agency it thought it was.… pic.twitter.com/aFMmki9Zln
— Max Karpis (@maxkarpis) September 16, 2026
Systemic Problem
The breach exposes a structural weakness in how financial institutions handle law enforcement data requests. Revolut’s compliance staff were, by one insider’s account, “so scared of government agencies that they are almost over-compliant.” A valid sender domain was treated as sufficient verification. No out-of-band confirmation call was made. No one questioned why an Italian municipal office was requesting data on citizens across 28 countries.
The same KYC infrastructure that compels customers to surrender passport scans, biometric selfies, and financial records under threat of frozen accounts became the precise mechanism through which that data was exfiltrated. The attacker didn’t need to write a line of malicious code. They weaponised the compliance process itself.
Sources: @ualliku reporting, public disclosures by affected individuals, leaked correspondence published by Duel (@korraflow), technical analysis by Mark Karpelès, and reporting by International Cyber Digest and Max Karpis.
