Revolut data theft: when the ‘police request’ is the attack
In mid-September 2026 a hacker using the alias ‘IAmNotAVillain’ claimed to have stolen data on roughly 680 to 700 Revolut customers and demanded a $3 million ransom. According to reporting by SecurityWeek and Euronews, the data was not taken by breaking into Revolut’s systems. It was requested, through what appeared to be legitimate Italian government channels, and handed over. For every organisation that receives disclosure requests from police, courts or regulators, this is the case study of the year.
What is reported to have happened
SecurityWeek reports that attackers compromised a government employee’s email account using infostealer malware, then used it to send fraudulent legal requests to Revolut Bank UAB, the group’s Lithuania-based subsidiary, over roughly five months. The requests were reportedly complied with without independent verification. Euronews reports that Italian investigators are examining a compromised institutional email account at the Reggio Calabria prefecture, and that the operation was described by cybercrime police as highly sophisticated.
The targets were reportedly selected because blockchain analysis suggested they held significant cryptocurrency. Euronews reports the stolen information includes passport and driving licence details, identity documents and photographs, and that customer funds were not touched. The attackers also claim to have taken 147GB of data from the Italian authorities themselves.
Prosecutors in Reggio Calabria, Italy’s national anti-mafia and counter-terrorism directorate, the Italian data protection authority and the cybercrime police are all reported to be involved. A Revolut spokesperson told SecurityWeek that the company had not received any direct contact or demand from the group making the claims. Many details remain allegations from the attackers, and the investigation is ongoing.
- Attack type
- Impersonation of a public authority using a genuine but compromised government mailbox.
- Customers affected
- Around 680 to 700, mostly in Europe, according to reports.
- Data
- Identity documents, contact details and financial information, according to reports and attacker claims.
Why this should worry every DPO
Most organisations have a process for answering police and regulator requests. Far fewer have a process for proving the request is real. That gap is exactly what was exploited here, and it is not unique to banks. Telecoms providers, retailers, healthcare organisations, employers and software platforms all receive such requests.
Three features make this attack hard to spot:
- The channel was genuine. Messages came from a real government system, so domain checks and email authentication would have passed.
- Authority discourages questions. Staff are understandably reluctant to push back on what looks like a legal order.
- Repetition builds false trust. Once a “contact” has been dealt with a few times, later requests get less scrutiny, not more.
Under the UK GDPR and EU GDPR, disclosures to law enforcement can be lawful, but only when they are genuine, necessary and proportionate. Handing personal data to a criminal who is impersonating a public body is a personal data breach, and the disclosing organisation owns the consequences.
“A trusted sender address is not proof of a trusted sender. Verification has to happen outside the channel the request arrived on.”
— Praeferre analysisWhat to do now
- Centralise disclosure requests. Route every police, court and regulator request through one trained team, not whoever happens to receive it.
- Verify out of band. Confirm each request by calling the issuing authority on a number you obtained independently, never one in the request itself.
- Check the legal basis and scope. Ask what power the request relies on, and disclose only the minimum data necessary.
- Escalate unusual patterns. Repeated requests about customers with a shared trait, such as high balances or crypto holdings, should trigger a review.
- Log and review every disclosure. Keep records of who asked, what was verified and what was sent, and have your DPO sample them regularly.
- Rehearse it. Include a fake authority request in your incident response and social engineering exercises.
Praeferre’s DPO as a Service helps organisations design disclosure procedures that stand up to this kind of pressure, and our GRC automation platform keeps request logs, approvals and evidence in one auditable place. See our guide to the UK GDPR.
Get experienced DPO support to harden your disclosure and breach response processes.
Talk to a DPOCommon questions
According to reports, attackers did not break into Revolut’s systems. They allegedly used a compromised Italian government email account to send fraudulent legal requests, which were answered. The investigation is ongoing and many details are claims by the attackers.
Yes. If personal data is disclosed to someone without authority to receive it, that is a personal data breach under UK and EU GDPR, and it may need to be reported to the regulator and to affected individuals.
Contact the issuing authority through independently sourced contact details, confirm the officer and reference number, check the legal power relied on, and have a trained team approve the disclosure.
Sources
- Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom — SecurityWeek, 17 September 2026
- Revolut hack: criminals steal data of 700 European clients, demand $3m ransom — Euronews, 17 September 2026