Sign up
Subscribe
Home / news / Hackers Raise Revolut Customer Data Ransom Demand After 12 September Breach
news

Hackers Raise Revolut Customer Data Ransom Demand After 12 September Breach

Hackers Raise Revolut Customer Data Ransom Demand After 12 September Breach

Attackers who hit Revolut on 12 September have now given the company a 24-hour deadline to pay in cryptocurrency, after first demanding 10,000 bitcoin. For high-risk payment businesses, the useful detail is not the theatrics: the attackers used a compromised Italian government email account to make what Revolut’s internal compliance treated as a legitimate data request.

  1. The group says it has data on 680 affected customers and is threatening to sell the records to other criminal groups if payment does not arrive within a day. According to the attackers, most of the victims are in Switzerland and France, with the rest spread across 31 other countries, mainly in Europe.
  2. The initial demand was 10,000 bitcoin, so this is already the second ultimatum. The attackers said the operation was run from Italy and that they targeted “whale accounts” — Revolut customers with large crypto wallets — using a compromised government mailbox.
  3. Italian media reported that IAmNotAVillain obtained about 147 GB of files from Italian law enforcement systems. The stolen material reportedly includes passport and driver’s licence copies, verification selfies, account statements, withdrawal records, and full transaction histories, including bitcoin activity.
  4. FT and Italian media identified the hacked mailbox as part of Italy’s PEC (Posta Elettronica Certificata), a certified email system used for corporate and government correspondence. Journalists linked the mailbox to Italy’s Ministry of the Interior, while some Italian outlets said it was an address for the Prefecture of Reggio Calabria.
  5. That detail matters because Revolut treated the message as a normal lawful request after its internal compliance checks. In other words, the company did not see a regulator’s request in front of it; it saw what looked like official correspondence from a public body, and staff handed over the data.

Italy’s cyber agency CERT-AGID warned back in June that PEC does not guarantee the security of message content, and it had already recorded more than 650 cases of unlawful use of PEC accounts since the start of the year. For PSPs and banks, that is the whole point: a trusted government-style inbox can still be the entry point for a data extraction request if the sender has been compromised.

Weekly high-risk digest

Regulation, sanctions and payment news across your verticals — once a week, free.

Please check your inbox and click the link to confirm your subscription.

Please enter a valid email address!