Revolut Data Breach (Fake Government Request, September 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·g2tMek…9wAiSummary
On September 12, 2026, Revolut confirmed that an unauthorized third party had obtained sensitive data belonging to approximately 680 customers by submitting fraudulent information requests from a compromised email account operating inside Italy's Ministry of the Interior domain (pec.interno.it), which passed SPF, DKIM, and DMARC authentication checks. The exposed data reportedly included passport copies, identity verification selfies, IBANs, account statements, and full Bitcoin transaction histories. Revolut stated that its own systems and customer funds were not compromised, characterizing the incident as a social engineering attack against its data-request verification procedures rather than an intrusion.
Connected Entities
5 entities · 60 linked investigations- Monero→mentioned with→Bitcoin(60%)
- Monero→mentioned with→ZachXBT(65%)
- ZachXBT→mentioned with→Bitcoin(65%)
- Revolut Data Breach (Fake Government Request, September 2026)→mentioned with→Monero(70%)
- Revolut Data Breach (Fake Government Request, September 2026)→mentioned with→Bitcoin(80%)
- Revolut Data Breach (Fake Government Request, September 2026)→mentioned with→ZachXBT(65%)
- Revolut Data Breach (Fake Government Request, September 2026)→mentioned with→Revolut(70%)
- Revolut→mentioned with→ZachXBT(65%)
- Revolut→mentioned with→Bitcoin(70%)
Timeline(7 events)
1 April 2026
Approximate start of the fraudulent data request campaign, based on reporting that the operation ran for approximately five months before discovery. The attackers allegedly used a compromised pec.interno.it email account to submit fraudulent law enforcement requests to Revolut Bank UAB.
SecurityWeek11 September 2026
Affected Revolut customers began receiving breach notification emails disclosing that their personal and financial data may have been shared with an unauthorized third party.
TechCrunch12 September 2026
Revolut publicly confirmed the breach to TechCrunch and other outlets, describing 'a sophisticated external impersonation scam' using a legitimate government agency email domain. ZachXBT flagged the customer notification on the same day and assessed it as a targeted high-net-worth operation.
TechCrunch / The Block16 September 2026
The threat actor group 'iamnotavillain' posted a public extortion demand of 6,000 Monero (approximately $3 million) with a 24-hour deadline, threatening to sell the stolen customer records. The group disclosed using blockchain analysis to select the 680 targeted high-net-worth accounts.
Decrypt / Irish Times16 September 2026
Additional reporting identified the compromised email account as associated with the pec.interno.it domain (Italy's Ministry of the Interior PEC system), specifically the Prefecture of Reggio Calabria. Hackers also claimed to have extracted 147GB of data from Italian law enforcement systems.
Irish Times / Security Affairs17 September 2026
Revolut stated it had 'not received any direct contact or demand' from the actors behind the extortion claims. The UK Information Commissioner's Office confirmed it had received a breach report and was assessing the matter.
Irish Times / MLex17 September 2026
Cybersecurity firm Hudson Rock reported approximately 300 compromised pec.interno.it webmail credentials in its database, suggesting the attackers obtained access via infostealer-harvested credentials rather than directly targeting government employees.
SecurityWeek / CyberInsiderDecision Log
- hash: DVtQRKFzeZraBnGyePKm7Z6U5xQ4AD7yqGVMj1mLx7is
This investigation is cryptographically anchored to the Solana blockchain (1 event). 15 of 17 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/18/2026, 5:06:58 PM
last updated: 9/19/2026, 12:01:36 AM
avoid.net — verified advice for a post-truth world