Data handed over to someone posing as a government agency: identity documents, verification selfies and full transaction history, Bitcoin included
This was not an intrusion: Revolut handed the data over itself, believing it was answering a government agency. A fraudulent information request came from an unauthorised account using the REAL email domain of a government agency — not a lookalike, the authentic one — and therefore passed sender authentication checks. In the notice sent to customers the company writes that it fulfilled the request «under the reasonable belief that it was an authentic government agency request». According to Revolut's notice, made public on 11 September 2026 by investigator ZachXBT who shared a copy, the data handed over includes: full name, date of birth, occupation, postal address, email and phone number; copies of identity documents (passport or driving licence) and the verification selfies submitted at onboarding; and on the financial side IBANs, account status and opening date, Bitcoin wallet reference numbers appearing in account statements, withdrawal records and the complete transaction history, including Bitcoin transfers. Revolut specifies that biometric facial telemetry data — distinct from the selfie images, which did leak — was not part of the disclosure. On 12 September 2026 a spokesperson publicly confirmed the episode to TechCrunch, calling it «a sophisticated external impersonation scam», and stated that «Revolut systems and customer funds are unaffected»: there were no account takeovers and no withdrawals. The company blocked the email address, alerted the government agency involved, law enforcement and financial regulators, and notified affected customers directly. WHAT WAS NOT KNOWN on 12 September, and it mattered: Revolut said a «limited» number of customers was affected but refused to give the figure or say which markets (see the 15 September update at the end); it does not name the impersonated agency; and it does not explain how a third party came to use its official domain. ZachXBT notes the number of accounts appears contained but that the attack seems aimed at high-net-worth individuals. The date on which the data was actually handed over is not known: the date recorded here is that of the notification emails received by customers. UPDATE 14-15 September 2026 — THE DATA IS NOW BEING PUBLISHED, NOT MERELY HELD. Accounts claiming to be behind the attack have opened a public extortion campaign across several Telegram groups. The Register, which saw those posts directly, reports that they contain snippets of data apparently belonging to high-profile individuals — chief executives, professional sportspeople, performing artists — and that the posters are threatening to release «more and more data every day until Revolut pays for leaking their customers», demanding a ransom of 10,000 bitcoin (over USD 780 million at 14 September 2026 prices). Recorded Future News reports the same demand and adds two elements: a customer whose data was circulated as proof did not dispute its authenticity, and among those publicly saying they were affected is Mark Karpelès, former chief executive of Mt. Gox. The Telegram account was subsequently suspended. Revolut, approached by both outlets, declined to comment on the existence of the ransom demand. BE CLEAR ON WHAT IS PROVEN AND WHAT IS NOT: that the extortion campaign exists and that excerpts of the data are circulating is documented by two independent outlets that saw the posts first-hand; that whoever is publishing them is genuinely the party that took the data remains THEIR claim, not an established fact, and no authority has confirmed it. A further UNCONFIRMED indication, which we report because it bears directly on readers in Italy: again according to Recorded Future News, the images circulated by that account suggest the fraudulent email originated from an ITALIAN domain. Italian authorities approached by the outlet did not respond, Revolut still does not name the agency, and the outlet itself states that not all details contained in the posts could be verified: this is an indication, not a finding. Sources close to the company tell The Register that the share of customers affected is small and that ongoing investigations and confidentiality obligations prevent it from saying more. It is not known whether the same compromised domain was used against other financial firms. UPDATE 15 September 2026 — THE FIGURE ARRIVES, AND THE REGULATORS SPEAK. The Financial Times, picked up by Reuters and by subsequent coverage, puts a number on the episode for the first time: 680 customers were affected, and Revolut has contacted all of them directly. The figure does not come from a company statement — Revolut had consistently refused to give one — but from press reporting: the company has neither denied nor publicly confirmed it. On the markets involved, something is finally visible: Irish public broadcaster RTÉ reports that 12 of the 680 are in Ireland, out of roughly 3.4 million Revolut customers in the country — a sign that the individuals were picked one by one, not lifted from an entire market. For Italy there is still no figure. On the authorities' side, silent until 14 September, there are now two public statements, and they should be read for what they actually say: the UK's ICO, the data protection regulator, states «we can confirm we have received a report and are assessing the information provided» — that is a preliminary assessment, NOT the formal opening of an investigation, and several outlets have wrongly reported it as one; the FCA, the UK financial regulator, says it is «aware of the reported incident involving Revolut» and is «engaging with the firm to understand the impact». Neither has announced any enforcement step. Meanwhile the extortion has not stopped: the group claiming the attack calls itself «Revolut Smilik» and has confirmed it wants a payment, repeating that it will publish «more and more data every day» until one arrives. Revolut still declines to comment. UPDATE 16-17 September 2026 — THE CHANNEL HAS A NAME AND IT IS ITALIAN, AND THE RANSOM COLLAPSES FROM 780 MILLION TO 3. (1) HOW THE REQUESTS ARRIVED. Since 12 September one precise question had gone unanswered: how did an outsider come to write from an authority's authentic domain? The channel the requests travelled on is now known: PEC, Italy's certified email system, the legally recognised service used by public administrations, companies and private citizens. According to Corriere della Sera sources, picked up on 16 September by Il Fatto Quotidiano and MilanoFinanza, the mailbox used is said to be that of the Prefecture of Reggio Calabria; the same name appears in a parliamentary question tabled by Democratic Party senators Lorenzo Basso and Antonio Nicita. BE CLEAR ON WHAT IS NOT ESTABLISHED, because the difference is substantial here: it is NOT settled whether the mailbox was genuinely taken over by someone — forensic experts are circulating the hypothesis of an infostealer, that is credentials stolen from a computer — or whether the sender was spoofed from outside. These are two scenarios with very different consequences for anyone using PEC, and the investigations exist precisely to tell them apart: until they do, the graver version is not the one written here. Italy's postal police is investigating for unauthorised access to a computer system and computer fraud; the National Cybersecurity Agency and the Bank of Italy are carrying out their own checks; the Italian data protection authority has opened enquiries. Italian authorities approached by the Irish Times declined to comment, while confirming that investigations are under way. The perpetrators further claim to hold 147 GB of material — 36,393 files in 5,223 folders — taken from Italian law enforcement systems: that is THEIR claim, verified by nobody, and should be read as such. (2) THE RANSOM DEFLATES. On 16 September the group published a 24-hour countdown and lowered its demand from 10,000 bitcoin to 6,000 monero, roughly USD 3 million, threatening otherwise to sell the files of the 680 customers to other criminal groups. The Financial Times reports this, having been shown a 60-second screen recording containing passports, driving licences and banking records, and CoinDesk picked it up on 16 September along with other outlets on 17 September. For the first time Revolut says something about the ransom, after days of «no comment»: «Revolut has not received any direct contact or demand from the individuals or group making these claims.» How to read that: a demand published on Telegram with a timer but never delivered to the company is pressure aimed at the public and the victims, not a negotiation under way; and a price falling from over 780 million to 3 in two days says above all that nobody is paying. (3) WHERE THE 680 ARE. Most are said to be in Switzerland and France, with residents of some thirty other countries — including the UK, Germany and Spain. This too is attributed to the attackers and not confirmed by Revolut. For Italy there is still no figure for affected customers: in this affair Italy appears as the origin of the channel used, not as the targeted market. (4) NOTHING HAS CHANGED ON THE REGULATORS, and this needs saying because the opposite is being written everywhere: numerous outlets, Italian ones included, state that the UK's ICO «opened an investigation» on 14 or 15 September. The ICO's own words are unchanged — it has received a report and is assessing the information provided — and on 15 September MLex, the specialist regulatory outlet, still headlined that the report «is being assessed». Until an act or a sentence from the authority says otherwise, the weaker verb is what stands here. Revolut has published nothing about the incident on its own X account: the latest post is from 3 September and concerns conditional approval from the US OCC. UPDATE 17 SEPTEMBER 2026 — WHERE THE CREDENTIALS CAME FROM, AND WHICH GROUP ENTITY RECEIVED THE REQUESTS. (1) For the first time there is a figure with a name attached instead of a generic hypothesis. Threat intelligence firm Hudson Rock says it holds roughly 300 compromised pec.interno.it webmail credentials in its own database — the certified-mail domain of the Italian Ministry of the Interior, which the Prefectures report to — all originating from machines previously infected by infostealers, the programs that harvest passwords saved in a browser. The firm draws an assessment from this, and words it carefully: the attackers may have bought or reused credentials already stolen by others, without needing to infect an Italian government employee themselves. CyberInsider reported this on 16 September 2026 and SecurityWeek on 17 September 2026. WHAT CHANGES AND WHAT DOES NOT: what changes is that the «infostealer» hypothesis now has a name and a number behind it, instead of being talk circulating among forensic experts; what does not change is that it remains unproven. A private firm's assessment is not the outcome of an investigation, and no Italian authority has yet said whether the mailbox was actually taken over or whether the sender was spoofed from outside. So both hypotheses stand here, exactly as before. The same articles also report — as the attackers' claim, not as verified fact — that a recovery address was added to the mailbox and the traffic monitored continuously, with outgoing fraudulent messages deleted. (2) IT IS NOW KNOWN WHICH GROUP ENTITY RECEIVED THE REQUESTS: not the British entity but Revolut Bank UAB, the group's Lithuanian bank, which serves customers in the European Economic Area, Italy included. Both outlets state this. (3) THE DEADLINE HAS PASSED AND NOBODY KNOWS HOW IT ENDED. The 24-hour countdown opened on the afternoon of 16 September expired on the afternoon of 17 September: as of the evening of 17 September no source reports a payment, a bulk publication of the 680 files, a sale to other groups or a fresh demand. Not knowing how it went is not good news: it only means nothing public has happened. The extortion remains open. On its own X account Revolut has now been silent about the incident for two weeks: the latest post is still the 3 September one about the OCC. UPDATE 19 SEPTEMBER 2026 — THE EXTORTION GOES QUIET, AND THIS ENTRY STOPS BEING FLAGGED AS «ONGOING». Forty-eight hours past the ransom deadline — the countdown expired on the afternoon of 17 September — still nothing public has happened: no payment, no bulk publication of the 680 files, no sale to other criminal groups, no fresh demand, no new claim. The coverage in this window repeats what was already known, with no new facts. Revolut remains silent about the incident on its own X account: the latest post is still the 3 September one about the OCC. So one thing changes, and it concerns how this case is displayed: until today the home security monitor flagged it as «ongoing», the state reserved for what is happening as you read it — an attack under way, funds moving, withdrawals still frozen. That is no longer the case here: the handover of the data was completed on 11 September, the threat to publish has been static for two days, and the Italian data protection authority's enquiries and the UK ICO's assessment are proceedings, not emergencies. The case therefore moves to the «open» state: not closed — the data is out and stays out — but nothing is happening right now. This is not a downgrade of how serious it is, which is unchanged, and it is reversible within an hour: if the 680 files are published or sold, or a new demand arrives, this entry returns to «ongoing» the same day. UPDATE 22 SEPTEMBER 2026 — THERE ARE TWO CLAIMED PERPETRATORS AND THEY ACCUSE EACH OTHER, THE DATA WAS ALREADY OUT IN JULY, AND MEANWHILE THE TEXT MESSAGES HAVE STARTED. (1) IT IS NOT ONE GROUP, AND UNTIL TODAY THIS ENTRY NAMED ONLY ONE: the correction comes first. Above you can read that the group «calls itself Revolut Smilik». In fact TWO Telegram channels claimed the attack: «IAmNotAVillain», the one behind the 6,000 monero demand (about 3 million dollars), and «Revolut Smilik», the one behind the 10,000 bitcoin demand. The former claims the latter is «an impersonator and scammer who used to work with us», who was handed a small sample of the data and is now claiming the whole breach as his own, and warns victims not to negotiate with anyone else. Both channels were suspended by Telegram; «iamnotavillain» later reappeared on a website of its own. This is reconstructed by KELA (analysis updated 15 September 2026) and BankInfoSecurity (15 September 2026). WHAT IT MEANS FOR THE READER: anyone among the 680 who gets contacted cannot tell from the name who actually holds their file — and the very fact that a sample passed between two parties means the data has already circulated. Which of the two versions is true has been established by nobody: these are criminals' competing claims, and we report them as such. (2) THE DATA WAS OUT BY LATE JULY AT THE LATEST — TWO MONTHS BEFORE CUSTOMERS WERE NOTIFIED. BankInfoSecurity reports that those blackmailed include Mark Karpelès, former CEO of Mt. Gox, crypto entrepreneur Marc Zeller and Felix Romer, founder of the gambling platform Gamdom, along with other industry figures, contacted directly by the perpetrator. One victim documented receiving extortion threats with Discord chat screenshots dated 26 JULY 2026, roughly two months before Revolut made the episode public. PRECISION ABOUT DATES IS NEEDED HERE, because it is the point on which this entry could most easily go wrong: the incident date remains 11 September 2026 because that is the verifiable date of the notification emails to customers, and the actual date the data was handed over is still not established either by Revolut or by any authority. What is now documented is something else, and it is enough to change how the case reads: the extortion of individual victims was already under way in July. Anyone who got the email on 11 September was not being told about something that had just happened. (3) HOW LONG IT ALLEGEDLY LASTED, AND WHY THE LITHUANIAN BANK SPECIFICALLY. According to the account the perpetrators gave the Financial Times, relayed by SecurityWeek on 17 September 2026, by American Banker on 18 September 2026 (updated 20 September) and by Cybernews, Revolut answered the fraudulent requests for about FIVE TO SIX MONTHS, not on a single occasion. The perpetrators say they picked Revolut Bank UAB, the Lithuanian subsidiary, precisely because it is obliged to answer a European Investigation Order — the cross-border demand for evidence that one EU member state can send another: they did not get around a compliance procedure, they targeted the duty to comply itself. They also say they selected their targets through on-chain analysis, identifying Revolut accounts holding significant crypto balances — which explains why the 680 are almost all people with visible wealth rather than a random slice of the customer base. American Banker adds the harshest detail: in at least one case a request submitted in the wrong form raised no suspicion, and Revolut staff reportedly explained how to correct it. IMPORTANT, AND DECISIVE: this entire paragraph is the PERPETRATORS' OWN ACCOUNT, given to the press and amplified from there. Revolut has confirmed neither the duration nor the number of requests, no authority has established it, and Cybernews itself headlines it as a claim. We do not write it as fact: we write it as what it is, a self-serving version which nonetheless comes from the only party that knows what happened, and which so far has not been denied. (4) THE EXTORTION SITE, AND ITS NUMBERS. KELA's analysis describes the infrastructure: a static page hosted on GitHub Pages, domain and DNS at GoDaddy, payment subdomain on GoDaddy Payments — something thrown together quickly with free or near-free services, not a structured organisation. The page displays screenshots presented as proof of the exchanges with the Italian mailbox and with the address [email protected], accuses Revolut of ignoring the breach notifications, and offers a contact via Telegram and Session to journalists and affected people alike. It claims nineteen «Document Revolut» archives and a 326 MB folder containing 688 files. A NOTE ON THE NUMBERS: 688 files are not 688 customers, and they do not match the 680 reported by the Financial Times; these are counts published by the perpetrators on their own site, not verified data. (5) THE MOST USEFUL THING TO KNOW TODAY: THE TEXT MESSAGES HAVE STARTED. Malwarebytes, which spotted it first (17 September 2026), and Infosecurity Magazine (21 September 2026) document a smishing campaign against Revolut customers. One affected customer received the message on Monday 14 September 2026, two days after the public announcement, and — this is the detail that makes the scam work — the text appeared IN THE SAME THREAD as genuine Revolut messages, slotting into the real conversation. The link leads to a page that asks for access to the phone's camera and, if granted, imitates Revolut's live video identity check, the one that asks you to turn your head, before asking for your password. The point is to harvest a selfie or video that can be reused to pass verification elsewhere or to make the next scam convincing. WHAT IS NOT PROVEN, and the company that found the campaign says so itself: Malwarebytes writes that «we don't yet know whether the phishing campaign is using data exposed in the breach or whether unrelated scammers are exploiting news of the incident to target Revolut customers more broadly». The link to the breach is NOT treated as established here — and it is also why this campaign does not become a separate Revolut incident: third-party phishing is not the provider's own act. For the reader it makes little difference, because the defence is the same either way, and it is set out below. (6) WHY THIS ENTRY STAYS «OPEN» AND DOES NOT RETURN TO «ONGOING». On 19 September this entry set three conditions for returning to the «ongoing» state: bulk publication of the 680 files, their sale to other groups, or a fresh ransom demand. As of today none of the three has happened, and no source reports a payment. The extortion site is not a new fact — it already existed on 15 September, so before that decision: it simply had not been recorded here. The text-message campaign is the work of third parties and is not attributed to Revolut. The state therefore remains «open»: the case is not closed, the data is out and stays out, but nothing is happening right now that touches systems or funds. The earlier commitment still stands: if the files are published or sold, or a new demand arrives, it returns to «ongoing» the same day. On its own X account, Revolut still says nothing about the incident.
What to do
Your money is not at risk and there is no reason to empty the account: Revolut states that systems and funds are unaffected, and nobody accessed the accounts. The risk here is a different one — your identity — and since 14 September 2026 it has got worse, because the data is no longer merely in someone's hands: it is being published in instalments, with a stated threat to increase the volume every day. As of today we also know how many people are involved: 680. If you have not had a direct notice from Revolut you are most likely not among them, and for exactly that reason treat as suspicious any message — email, text or phone call — telling you otherwise: right now «you are one of the affected customers» is the easiest sentence in the world to fake. There is only one way to check: open the in-app support chat yourself. If you received a notification email from Revolut on 11 September 2026, assume your documents are already out and act accordingly now, not in six months. Whoever holds that data knows your name, date of birth, address, IBAN, when you opened the account and what went through it: they can build a call or an email that sounds authentic in a way no generic phishing ever does, quoting real transactions back to you. Practical rule: no bank, no police force and no tax authority will ever ask you to move money to a «safe account», nor for codes, PINs or recovery phrases. If you get an unsolicited call, hang up and contact support yourself from the in-app chat, never from numbers or links you were given. During a phone call, NEVER approve an in-app notification, a payment or a two-factor prompt. Change your Revolut password and the password of the email account linked to it, and check that two-factor authentication is on for both: not because they were breached, but because anyone holding your data starts with an advantage on any account-recovery procedure. If you hold crypto, note that Bitcoin wallet references and withdrawal history were disclosed too: the excerpts published so far concern mainly people with visible wealth, so expect targeted, tailored attempts, and consider not publicly linking your identity to what you hold. Keep the notification email and ask Revolut in writing for the exact copy of what was disclosed about your account: it is your right of access and you will need it if someone later opens something in your name. Because passport or driving licence copies were disclosed, over the coming months check that no accounts, contracts or loans appear in your name that you did not request, and consider flagging the document as compromised when asked to use it for remote identity verification. Two new warnings, as of 16 September 2026. The first is for readers in Italy: because the fraudulent requests travelled over PEC apparently traceable to a Prefecture, expect messages over the coming months presenting themselves as a Prefecture, a Ministry, the police or the tax police, possibly citing this very affair. Hold on to one point that has no exceptions: an authority never asks you for money, credentials, codes or access to your accounts by certified email, email or phone, and never rushes you. If you receive something of the sort, do not reply and do not click: verify by calling the body on the number listed on its official website. The second concerns the countdown: the perpetrators threatened to sell the files to other criminal groups if they are not paid. The deadline passing does not put you in the clear — if anything the opposite, because if the data is sold on, the number of people holding it grows. Treat the exposure as permanent: the countermeasures that matter are the ones that stay valid over time — flagging the document as compromised, periodically checking that no accounts or loans appear in your name, distrusting anyone who calls quoting your real transactions — not twenty-four hours of vigilance. And be especially wary of anyone who, once the deadline has passed, offers for a fee to «remove your data from the sale». Finally, two things about the ongoing extortion: do not go looking for the channels where the data is being posted and do not engage with them, and absolutely distrust anyone offering, for a fee, to «remove» or «protect» your data, or promising «refunds», «compensation» or «verification» tied to this very episode: clones follow every such case, and here they have real material to quote. One last thing, if you are among the 680 and want the matter put in front of an authority: the complaint goes to the data protection regulator of your own country — in Italy, the Garante per la protezione dei dati personali. In the UK the ICO has received the company's report and is assessing it, and the FCA is engaging with Revolut, but neither has opened proceedings. In Italy the picture has changed since 15 September: as of 16 September the Italian data protection authority has opened enquiries and the postal police is investigating the PEC channel used for the requests, so a file already exists — but it concerns the origin of the attack, not your individual case. Your complaint is still worth making: it is what ties your name to the affair if you later need to show you were involved. One practical addition as of 17 September 2026, for anyone in Italy who holds a PEC certified mailbox — professionals, businesses, anyone using one for work: the account published today involves certified-mail credentials that ended up in databases of passwords stolen by infostealers. It has nothing to do with your Revolut account, but it is the right moment to change your PEC password, turn on two-factor authentication if your provider offers it, and open the mailbox settings to check there is no recovery address or automatic forwarding rule you did not set yourself: that is exactly the kind of change that stays invisible for months. As for the ransom deadline, which passed on the afternoon of 17 September with no known outcome: it changes nothing about what you should do. The countermeasures that matter are still the ones that hold over time. One clarification as of 19 September 2026, so the tone of this page does not mislead: two days after the ransom deadline the threat to publish is static — not withdrawn, static. That is not an all-clear. The identity documents, selfies and transaction histories that went out are out for good, and the most dangerous moment for those affected is not when the data gets published, but when, months later, someone uses it on the phone to be believed. The habits described above should be kept anyway, and indefinitely. Three additions as of 22 September 2026, and the first is the most concrete thing on this page. ONE: the text messages have started. If you get a message that looks like Revolut asking you to «verify your identity» via a link, do not open it — not even if it appears in the same conversation as genuine Revolut texts, alongside the real codes and notifications you have already received. That is exactly how they are arriving: the sender is spoofed so the message slots into the genuine thread, which is why the usual advice to «check the sender» does not work here. Above all: NO legitimate Revolut identity check happens on a web page opened from a link received by text. If a page asks for camera access and has you turn your head the way the app does, then asks for your password, you are on a fake — close it, and if you already granted the camera or entered your password, change your password in the app immediately and tell support through the in-app chat. Video verification happens inside the app, opened by you. TWO: if someone contacts you claiming to hold your file, do not negotiate and do not pay, under either of the two names in circulation. There are at least two channels claiming the attack and each accuses the other of being a fraud: in that situation paying guarantees you nothing, not even by the blackmailer's own logic, because you do not know who actually holds your documents or how many copies exist. If you are contacted, save everything — screenshots, dates, usernames — and take it to the police and to your country's data protection authority: that is worth far more than any negotiation. THREE: if you are among the 680, do not assume your exposure begins on 11 September 2026. Some victims are documented as having been blackmailed as early as 26 July, and by the perpetrators' own account the requests went on for months. In practical terms: if over the past six months you received odd approaches, login attempts, verification requests or phone calls quoting real details about you, and you filed them away as coincidence, look at them again in the light of this affair — and if you suffered a loss, the date to put on your report is not necessarily September.
Source: ilfattoquotidiano.it ↗
verified on September 22, 2026
See the profile →