Skip to content
Fraud & Cybersecurity

Revolut faces $3m ransom claim after fake government request

A group calling itself iamnotavillain has publicly demanded $3m after Revolut disclosed data on about 680 customers following fraudulent requests from a genuine Italian government email address. Revolut says funds and systems were unaffected and it received no direct demand.

By FinTechPulse Editorial

Published
An oversized official wax seal on a brass letterbox set into a blank steel door, with paper documents spilling out onto the floor below it.

Revolut has disclosed personal and financial data belonging to about 680 customers after criminals used an email address on a genuine Italian government domain to submit fraudulent requests for customer information. A group calling itself iamnotavillain has since publicly demanded $3m, reported at the time as roughly £2.2m, and threatened to sell the data. Revolut says its own systems and customer funds were unaffected, and that it has received no direct contact or demand from whoever made the claim.

The incident matters to UK readers for two reasons. Reporting has said residents of other European countries, including the UK, were among those affected — though no UK regulator or first-party Revolut disclosure has published a confirmed UK victim count. More broadly, the episode is a live test of how a firm regulated for financial services should verify an "official" request before handing over identity and account data, when the request appears to come from an address on a genuine government domain.

What Revolut disclosed

The figure of 680 affected customers comes from Italy's interior undersecretary, who told parliament on 18 September 2026 that Revolut had confirmed the number to Italian authorities on 15 September, with eight of those customers Italian. Revolut's own public statement, as reported, referred only to "a limited number" of customers and did not itself confirm the 680 figure. That gap between an indirect official statement and the company's own wording should be read as exactly that — a gap, not a settled company disclosure.

Reported data categories include identity and contact details, copies of identity documents, verification images, account statements, IBANs, withdrawal information and transaction histories, including Bitcoin activity. Which of these fields applied to any individual customer is not established; the packet of reporting reviewed for this article indicates the categories varied between people, and no field-by-field breakdown has been published.

Revolut has said its internal systems and customer funds were unaffected. That is the company's own account of the incident, and it is an important distinction: this was not reported as a breach of Revolut's core banking infrastructure or a compromise of customer accounts. It was, on Revolut's account, an unauthorised disclosure that happened through the handling of requests that looked official but were not.

How the Italian government account was used

The email address involved was reportedly a PEC account — a certified email service used for legally recognised correspondence in Italy — associated with the Prefecture of Reggio Calabria. Italian investigators, including the postal police, opened a formal investigation, and Italy's national CSIRT (computer security incident response team) reportedly analysed a sample of the email traffic. As of the most recent reporting, it remained unresolved whether the account had been directly compromised or cloned; treat that mechanism as still under investigation rather than a settled finding.

What is established is that the address used was on an authentic Italian government domain, unlike a typical phishing scam that relies on a lookalike address. That distinction is likely why the requests were treated as credible enough to act on. How the mailbox was actually used to send them, and what documentary authority accompanied the emails, remains unresolved.

Why the ransom demand remains an allegation

A group using the name iamnotavillain has claimed responsibility and publicly demanded $3m, reportedly payable in Monero, with one account describing the sum as 6,000 XMR and a reported 24-hour deadline. Revolut has said it received no direct contact or demand from the party making these claims. As of the most recent reporting reviewed, there is no independent confirmation that Revolut paid anything, or that the complete dataset was subsequently sold.

Several things about this claim should not be merged or treated as confirmed. An earlier and separate claim reportedly involved a demand of 10,000 Bitcoin; the relationship between that claim and the iamnotavillain demand, and whether they involve the same actors, is unresolved. The alleged attackers have also claimed to hold 147GB and more than 87,000 files from Italian law-enforcement systems — a figure that comes from the attackers themselves and has not been independently verified. It should not be reported as established fact.

Key dates

DateEvent
11 Sep 2026Affected-customer notices reportedly begin circulating
12 Sep 2026Revolut's confirmation of the impersonation incident reported publicly
15 Sep 2026Revolut confirms 680 affected customers to Italian authorities, per interior undersecretary
16 Sep 2026Italian postal police investigation and public $3m demand reported
17 Sep 2026Guardian reports the demand and Revolut's statement that it received no direct contact
18 Sep 2026Interior undersecretary gives parliamentary response on the Reggio Calabria account
21 Sep 2026No verified payment, data sale or UK victim count found as of this reporting cut-off

The UK exposure

Reporting has attributed a claim that UK residents were among the affected customers to the alleged attackers, alongside customers described as mainly in Switzerland and France. No Revolut disclosure or UK regulator statement reviewed for this article gives a confirmed number of UK customers affected. Readers should treat the UK figure as unverified until Revolut, the Information Commissioner's Office (ICO) or the Financial Conduct Authority (FCA) publishes one.

It is also worth being precise about jurisdiction here: the investigation, the parliamentary questioning and the confirmed figures so far are Italian. There is no UK equivalent process reported, and this is not a UK regulatory finding.

What UK data-protection law requires

UK financial firms handling personal data are subject to the UK GDPR, which has applied since 1 January 2021. The underlying legislative text derives from the EU's General Data Protection Regulation and must be read together with post-Brexit amendments and the Data Protection Act 2018 for its current UK application. The ICO's guidance explains that Article 5(1)(f) and Article 32 of the UK GDPR require organisations to use technical and organisational security measures appropriate to the nature, scope, context and purpose of their processing, and to the risks the processing poses to individuals. This is a risk-based standard rather than a fixed checklist: the ICO's published guidance does not prescribe one universal method for authenticating a law-enforcement or government data request, whether that request originates in the UK or overseas.

Revolut's UK privacy notice states that it may share personal data with government, law-enforcement and tax authorities where necessary to meet legal or regulatory obligations. That is the normal, lawful reason such requests exist. It does not, on its own, establish that every request arriving from an official-looking address is genuine or that a firm has met its security obligations simply by receiving one.

The verification gap this incident exposes

The core problem this case illustrates is that an authentic sending domain proves the domain is real — it does not prove that the specific person using the mailbox has the identity, authority, legal power or entitlement to the particular records they are asking for. A compromised or misused mailbox on a genuine government system can look, from the recipient's side, indistinguishable from a legitimate request.

Possible additional controls that risk-management practice can draw on include independently verifying the requesting officer's identity through a separate, previously known contact channel, confirming the legal instrument or power cited, checking that the scope of the request matches what that power actually authorises, escalating high-risk or cross-border requests for senior approval, and keeping tamper-evident logs of how each request was received and actioned. None of these is set out by the ICO as a single mandatory workflow; they are described here as measures firms can weigh against the risk-based duty, not as rules this incident proves were broken.

Risks for affected customers

Revolut's statement that funds and systems were unaffected addresses one risk but not all of them. Disclosure of identity documents, verification images, account numbers and transaction histories can expose people to identity fraud, targeted phishing that references real account details to appear convincing, attempts at account takeover using stolen identity information, and in some cases concerns about physical safety where financial details point to wealth. None of this is confirmed to have happened to any specific customer in the sources reviewed, and readers should not assume it has. Anyone contacted by Revolut about this incident, or who has reason to believe they were affected, should treat unsolicited contact referencing their account with caution and use Revolut's own official channels, or the ICO's guidance on data breaches, to check what applies to them, rather than relying on messages that themselves claim official authority.

What to watch next

The open questions are largely in Italian and corporate hands for now: the forensic finding on whether the Reggio Calabria PEC account was compromised or cloned, any formal action by the ICO or FCA in the UK, a confirmed UK victim count, clarification of which Revolut legal entity processed the fraudulent requests, and whether the claimed dataset has in fact been sold or misused. None of these had been resolved as of the most recent reporting reviewed for this article.

Sources

  1. Atto di Sindacato Ispettivo n. 3-02788 (opens in a new tab)

    Senato della Repubblica · · Accessed

  2. Caso Revolut, l'hacker chiede riscatto di 3 milioni per i file rubati (opens in a new tab)

    Corriere della Sera · · Accessed

  3. Security outcomes (opens in a new tab)

    Information Commissioner's Office · Accessed

  4. Security (opens in a new tab)

    Information Commissioner's Office · Accessed

  5. Customer Privacy Notice (opens in a new tab)

    Revolut · Accessed

  6. Regulation (EU) 2016/679: General Data Protection Regulation (opens in a new tab)

    The National Archives · · Accessed