Revolut has promised to cover the cost of new identity documents for customers whose personal data was handed to hackers through a scam built on a real Italian government email account. Around 680 customers were affected after the bank answered fraudulent data requests that looked like legitimate law enforcement inquiries. Here is what happened, what was exposed, and what you should do if you use Revolut.
The short version: attackers took control of a genuine certified email account belonging to an Italian interior ministry office and used it to send official-looking data requests to Revolut over several months. Revolut, believing it was dealing with Italian authorities, complied. The incident was disclosed in September 2026; on October 7, Revolut’s CEO for Western Europe told BFM TV the company will pay for affected customers to replace identity documents and will not pay any ransom.
What actually happened in the Revolut data breach
On September 12, 2026, Revolut disclosed that an unauthorized third party had obtained sensitive customer data by impersonating a government agency. The attack was unusual because the hackers never breached Revolut’s own systems. Instead, they got hold of a real email account inside Italy’s certified government messaging system — the network Italian public bodies use to exchange official correspondence with outside organizations.
Cybersecurity firm Hudson Rock later traced the fraudulent requests to a compromised email account on the pec.interno.it domain, linked to the Prefecture of Reggio Calabria. The attackers submitted requests that read as routine official correspondence, including what appeared to be European Investigation Orders, and asked Revolut to identify clients tied to specific cryptocurrency transaction IDs.
Because financial institutions are legally required to hand over customer data when authorities request it as part of investigations, Revolut complied with the requests. It now appears the scam ran for roughly five to six months before being discovered, with around 680 accounts affected — reportedly concentrated among higher-net-worth customers and cryptocurrency holders, mostly in Switzerland and France.
How a genuine government email fooled one of Europe’s biggest fintechs
The mechanism is what makes this breach so alarming. This was not a fake domain or a cleverly misspelled sender address. It was a real, functioning government mailbox, accessed by criminals who most likely bought the stolen login credentials from infostealer malware logs traded on criminal marketplaces. Hudson Rock investigators identified more than 300 compromised credentials tied to that domain, suggesting the ministry itself was never directly hacked — individual logins were.
With a legitimate sender address, the requests cleared the basic authenticity checks most compliance teams rely on. Italy’s interior minister, Matteo Piantedosi, told lawmakers on September 30 that the address came from the Reggio Calabria police’s email system but was one that had never been used before — and argued Revolut could have and should have verified the requests with minimal due diligence.
Revolut’s CEO for Western Europe, Béatrice Cossa-Dumurgier, pushed back on that framing in her October 7 interview, saying government agencies are sometimes the weak link in the system and stressing that Revolut’s own systems were not compromised. The dispute highlights a genuine gray area: when a request arrives from an authentic government channel, how far is a bank supposed to go before treating it as real?
What data the hackers got their hands on
The exposed data is about as sensitive as it gets. According to reports, the attackers received identity documents including passports and driving licences, identity verification selfies, dates of birth and occupations, full contact details, account statements listing IBANs, and complete transaction histories covering both fiat currency and cryptocurrency transfers.
The hacker group calling itself IAmNotAVillain claimed it maintained access to the compromised email account for about six months. After Revolut refused to pay, the attackers began leaking customer records in a batch dubbed the Italy Files, reportedly including the data of 680 large cryptocurrency holders. Former Mt. Gox CEO Mark Karpelès was named in reports as one of the affected customers. The group reportedly started with an enormous Bitcoin demand before reducing it to roughly $3 million in Monero, then began offering the data at steep discounts — suggesting it struggled to monetize the leak.
Revolut’s response: ID document costs covered, no ransom paid
In her October 7 interview with BFM TV, Cossa-Dumurgier said Revolut has provided assistance to all 680 affected clients, 55 of whom are in France, and confirmed the company will cover the cost of replacing identity documents for anyone who needs to do so. She did not specify how much that could cost or whether any customer had requested it yet.
She also addressed the ransom question directly: Revolut will not pay ransoms to hackers. The company had previously said it did not receive a ransom demand, an apparent contradiction with the leaked ransom figures — one that Revolut has not publicly reconciled.
The incident drew attention from regulators, with the UK data protection authority and the Italian Postal Police investigating for unauthorized access and computer fraud. As with other major financial-sector breaches — including the recent FBI Accenture PeopleSoft breach — the notification and investigation obligations have kicked in under European data protection rules.
What to do if you are a Revolut customer
If you were one of the 680 affected customers, Revolut says it contacted you directly. Whether or not you were affected, the breach is a good prompt to tighten your own defenses.
1. Watch for targeted phishing
The leaked data includes enough detail — ID selfies, account statements, transaction histories — to build extremely convincing phishing or identity-theft attacks. Be skeptical of any message claiming to be from Revolut, a tax authority, or law enforcement asking for personal details or money. Revolut never asks for your PIN, password, or full card details.
2. Turn on two-factor authentication everywhere it matters
Strong two-factor authentication is one of the most effective defenses against account takeovers. The same discipline that protects your own accounts also protects the compliance teams at banks and fintechs — credential theft via infostealer malware is how this entire attack started.
3. Consider replacing compromised ID documents
Revolut has committed to covering the cost of ID document replacement for affected customers. If your passport or driving licence was exposed, replacing the document changes the numbers an identity thief would use, which is one of the few reliable ways to neutralize stolen identity data.
4. Monitor your accounts and credit reports
Keep an eye on account statements for unfamiliar transactions and check your credit reports for new accounts or inquiries you do not recognize. As the Pentagon DMDC breach showed, military-grade identity data circulates for years; the same will likely be true here.
The bigger lesson for fintech and compliance teams
The Revolut case is a wake-up call for any organization that handles official data requests. Sender authenticity is no longer enough: if government email accounts can be quietly held by criminals for months, compliance teams need out-of-band verification — a phone call, a known contact, a second channel — before releasing sensitive data. The same pattern of trusted-system compromise keeps appearing across the industry, from supply-chain attacks to the unpatched SharePoint servers behind the Warlock ransomware campaign.
For regulators, the incident raises uncomfortable questions about the security of government communication channels themselves. Infostealer-sourced credentials are cheap and plentiful, and certified email systems carry the one thing criminals need most: unquestioned trust.
Frequently asked questions
Was Revolut hacked?
Revolut says its own systems were not breached. Hackers controlled a real Italian government email account and used it to send fraudulent data requests that Revolut treated as legitimate law enforcement inquiries. No customer funds were affected.
How many Revolut customers were affected?
Around 680 customers had their personal data exposed, according to Revolut. The company said 55 of the affected clients are in France, with others concentrated in Switzerland and elsewhere in Europe.
What personal data was exposed in the Revolut breach?
Reports indicate the leaked data includes passports and driving licences, identity verification selfies, dates of birth, occupations, contact details, account statements with IBANs, and full transaction histories covering fiat and cryptocurrency transfers.
Will Revolut pay for new identity documents?
Yes. On October 7, 2026, Revolut’s CEO for Western Europe, Béatrice Cossa-Dumurgier, told BFM TV that the company will cover the costs for affected customers who need to change their identity documents.
Did Revolut pay the hackers a ransom?
No. The company has said it will not pay ransoms and previously stated it had not received a ransom demand, despite reports of demands starting high and later being reduced to around $3 million in Monero.
How did hackers get a real Italian government email account?
Cybersecurity investigators believe the criminals used login credentials stolen by infostealer malware and traded on criminal marketplaces, rather than hacking the ministry directly. More than 300 compromised credentials tied to the pec.interno.it domain were identified.
