Drooid Logo
Back to story perspectives

Full Breakdown

Revolut data breach and extortion attempt

By Drooid · · How we work

Core Event

In early September 2026 Revolut disclosed that it had supplied sensitive personal and financial information for a limited set of customers after responding to fraudulent requests that appeared to come from a legitimate Italian government email address. The breach affected roughly 680 European users and included passports, driver’s licences, verification selfies, addresses, phone numbers, IBANs and full transaction histories, including Bitcoin activity.

A hacker collective calling itself iamnotavillain posted a public ultimatum on 16 September 2026, demanding payment of 6,000 Monero (XMR) – about $3 million – within 24 hours or threatening to sell the data. The group released a short screen-recording showing the stolen documents and began publishing dossiers on a Telegram channel from 13 September 2026 onward.

Background & Context

The attackers exploited a compromised account on Italy’s certified email system (Posta Elettronica Certificata, PEC). By sending requests that passed standard domain-authentication checks, they convinced Revolut’s compliance team that the inquiries were official law-enforcement demands and obtained the targeted records over several months.

Italian prosecutors in Reggio Calabria, the National Anti-Mafia and Counter-Terrorism Directorate, and the Italian data-protection authority have opened investigations into the compromise of the government email account and the possible cloning of credentials.

Data & Statistics

  • Customers affected: approximately 680 European users.
  • Data types disclosed: passports, driver’s licences, facial verification photos, full names, dates of birth, residential and email addresses, phone numbers, occupation, IBANs, account statements, withdrawal records, and cryptocurrency transaction histories.
  • Ransom demand: 6,000 XMR (? $3 million) with a 24-hour deadline; the group claimed possession of 147 GB of data.
  • Public threat timeline: demand posted 16 September 2026; first public dossier released 13 September 2026.

Official Statements & Responses

The firm blocked the offending address, alerted the relevant government agency, law-enforcement, data-protection and financial regulators, and contacted the limited number of impacted individuals directly.

Italian authorities have launched criminal investigations into the intrusion of the PEC account and are examining whether the email was compromised or cloned.

Criticism & Opposition

Giulia Pastorella, a lawmaker from Italy’s opposition Azione party, warned that the breach could be “the tip of the iceberg,” questioning how many other government-issued emails might have been abused.

Cyber-security analyst Muhammad Yahya Patel described the incident as “deeply concerning” and emphasized that the exposed data constitutes a “complete identity-theft kit” that could be sold on the dark web.

Conflicting Reports & Gaps

  • Ransom amount: most sources cite a $3 million Monero demand, but some outlets reported a separate claim of 10,000 Bitcoin (? $780 million). No verification of the latter figure has been provided.
  • Number of victims: estimates range from “around 680” to “nearly 700”; Revolut has not released an exact figure.
  • Use of PEC: several reports attribute the compromised channel to Italy’s PEC system, while other investigations label the claim as unverified, noting that the specific government agency has not been identified.

What’s Next

Italian prosecutors and the National Anti-Mafia Directorate continue to investigate the source of the compromised email account and whether additional public bodies were affected. The UK ICO and FCA are reviewing Revolut’s compliance procedures, with supervisory hearings scheduled for later in the third quarter of 2026. Revolut has indicated that its core systems and customer funds remain secure, but the ongoing public release of dossiers suggests that the extortion campaign may persist unless a resolution is reached.