Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#1
Score
Cluster
mainnet-beta
Slot
448146300
Off-chain at
2026-09-18T17:07:08.528Z
Anchored at
Block time

Independent verification

1. Database (off-chain)
DVtQRKFzeZraBnGyePKm7Z6U5xQ4AD7yqGVMj1mLx7is
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (22059 chars)
{"actor":"system:backfill","investigation_id":"90b40c3c-e5f4-4306-b5dc-a1d036dbe1f0","kind":"publish","page_slug":"revolut-data-breach-fake-government-request-september-2026","published_at":"2026-09-18T17:07:08.308Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Revolut Data Breach (Fake Government Request, September 2026)","sections":[{"content":"Revolut confirmed on September 12, 2026 that it had disclosed sensitive customer data in response to fraudulent requests submitted from an email account operating within the domain infrastructure of a legitimate Italian government authority. The company described the incident as 'a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.' Revolut stated that approximately 680 customers were affected, that its internal systems remained secure, and that customer funds were not at risk. The company said it notified affected customers, alerted the relevant government agency, reported the incident to law enforcement, and notified financial regulators. Revolut has not publicly identified the specific government agency involved, though multiple news organizations have reported that the email account was associated with Italy's Ministry of the Interior via the pec.interno.it domain, specifically linked to the Prefecture of Reggio Calabria.","heading":"Incident Overview","severity":"high","sources":[{"credibility":1,"name":"Revolut confirms customer data breach through fake government requests","type":"news_article","url":"https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/"},{"credibility":2,"name":"Revolut says customer KYC, Bitcoin transaction data exposed after fake request from gov't domain","type":"news_article","url":"https://www.theblock.co/news/business/2026-09-12-revolut-says-customer-kyc-bitcoin-transaction-data-exposed-after-fake-request-from-govt-domain-414516"},{"credibility":2,"name":"Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom","type":"news_article","url":"https://www.securityweek.com/revolut-data-breach-5-months-680-high-profile-accounts-3m-ransom/"}]},{"content":"The attack exploited a procedural vulnerability in Revolut's government data-request handling rather than a technical breach of its systems. According to reporting by SecurityWeek and Security Affairs, the attackers allegedly obtained access to one or more employee accounts within Italy's official PEC (Posta Elettronica Certificata) email system — a state-regulated secure communications network used for official government correspondence — likely through infostealer malware that had previously compromised government employee credentials. Cybersecurity firm Hudson Rock reportedly identified approximately 300 compromised pec.interno.it webmail credentials in its cybercrime database, though Hudson Rock assessed that the attackers may have acquired existing stolen credentials rather than having directly infected Italian government employees themselves. Because the fraudulent requests originated from within a legitimate government domain's infrastructure, they passed SPF, DKIM, and DMARC email authentication checks — controls that verify a message passed through infrastructure authorized by a domain but do not confirm that the account holder is authorized or that the request itself is lawful. Security researchers have noted that this attack exploited a fundamental limitation of email-based verification: authentication protocols confirm message origin infrastructure, not the legitimacy of the sender or the request. Revolut's Lithuania-based banking subsidiary, Revolut Bank UAB, was the recipient of the fraudulent requests. The attackers reportedly operated undetected for approximately five months before the deception was discovered when Revolut contacted the agency to confirm the requests.","heading":"Attack Method and Technical Mechanism","severity":"high","sources":[{"credibility":2,"name":"Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks","type":"news_article","url":"https://securityaffairs.com/198922/data-breach/revolut-exposed-kyc-data-after-fraudulent-government-email-passed-security-checks.html"},{"credibility":2,"name":"Revolut Data Leak May Trace Back to Compromised Italian Government Accounts","type":"news_article","url":"https://securityaffairs.com/199180/data-breach/revolut-data-leak-may-trace-back-to-compromised-italian-government-accounts.html"},{"credibility":2,"name":"Revolut hackers used infostealer to hijack Italian government emails","type":"news_article","url":"https://cyberinsider.com/revolut-hackers-used-infostealer-to-hijack-italian-government-emails/"},{"credibility":2,"name":"Revolut Hackers Used Infostealers for Elaborate Social Engineering","type":"news_article","url":"https://www.infostealers.com/article/revolut-hackers-used-infostealers-for-elaborate-social-engineering/"}]},{"content":"The operation appears to have been deliberately targeted at high-net-worth cryptocurrency holders rather than being an opportunistic mass data collection. The threat actors, identifying themselves under the alias 'iamnotavillain,' disclosed that they used on-chain blockchain analysis to identify Revolut accounts with substantial cryptocurrency holdings, selecting approximately 680 targets they characterized as 'crypto whales.' Crypto investigator ZachXBT assessed the incident as likely limited in scope but targeted at high-net-worth users. The affected customers were reportedly concentrated in Switzerland and France, but according to the actors' claims, Revolut also disclosed data belonging to residents of 33 countries in total, including the United Kingdom, Germany, and Spain. The geographic concentration and deliberate victim selection via blockchain analysis distinguish this incident from broad credential-dump breaches and indicate a financially motivated operation with significant pre-operational intelligence gathering.","heading":"Targeted Nature of the Operation and Victim Profile","severity":"high","sources":[{"credibility":1,"name":"Hackers say they breached Italian state email to target Revolut 'crypto whales'","type":"news_article","url":"https://www.irishtimes.com/business/2026/09/16/hackers-say-they-breached-italian-state-email-to-target-revolut-crypto-whales/"},{"credibility":2,"name":"Revolut Crypto Breach Exposes Data of 680 High-Value Accounts","type":"news_article","url":"https://en.cryptonomist.ch/2026/09/16/revolut-crypto-breach-data/"},{"credibility":2,"name":"User Data Breach at Revolut Exposed High-Net-Worth Clients","type":"news_article","url":"https://coinfomania.com/user-data-breach-at-revolut-exposed-high-net-worth-clients/"}]},{"content":"According to Revolut's notifications to affected customers and corroborating reporting, the data disclosed to the fraudulent requester included: full names; dates of birth; occupations; residential and email addresses; phone numbers; copies of passports and driving licences; identity verification selfies submitted during KYC onboarding; IBANs and account-opening dates; account statements; withdrawal records; Bitcoin wallet reference numbers; and complete cryptocurrency transaction histories. The inclusion of full Bitcoin transaction histories alongside real-world identity documents and addresses creates a particularly acute risk profile for affected customers, as it enables actors to map cryptocurrency holdings to verified identities. Revolut's customer notification stated that verification selfies, account statements, and transaction histories 'may' have been included, indicating some uncertainty about the full scope per affected individual.","heading":"Data Exposed","severity":"critical","sources":[{"credibility":2,"name":"Revolut Data Breach Exposes Customers' Passport Copies and Full Transaction Histories","type":"news_article","url":"https://cybersecuritynews.com/revolut-data-breach/"},{"credibility":1,"name":"Revolut confirms customer data breach through fake government requests","type":"news_article","url":"https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/"},{"credibility":2,"name":"Revolut Hackers Demand $3M Monero Ransom, Threaten to Sell Customer Data","type":"news_article","url":"https://decrypt.co/378472/revolut-hackers-demand-3m-monero-ransom-threaten-to-sell-customer-data-report"}]},{"content":"On approximately September 16, 2026, the threat actors operating under the alias 'iamnotavillain' published a public extortion demand via a dedicated website, demanding 6,000 Monero (XMR) — valued at approximately $3 million at the time — with a 24-hour deadline, and threatening to sell the stolen customer records if Revolut did not pay. The group stated: 'all the data will be sold, and the blood will be on your hands.' Monero was selected for its privacy-preserving transaction properties. The Irish Times and other outlets reported that the group had also at one point cited a figure of 10,000 Bitcoin, though the $3 million Monero demand appears to be the publicly posted figure. Revolut stated that it 'has not received any direct contact or demand from the individuals or group making these claims.' There is no public confirmation as of the investigation date that Revolut paid any ransom, and no public confirmation that the data was sold or published.","heading":"Extortion Demand","severity":"high","sources":[{"credibility":2,"name":"Revolut Hackers Demand $3M Monero Ransom, Threaten to Sell Customer Data","type":"news_article","url":"https://decrypt.co/378472/revolut-hackers-demand-3m-monero-ransom-threaten-to-sell-customer-data-report"},{"credibility":2,"name":"Revolut hit with $3 million Monero ransom demand","type":"news_article","url":"https://betanews.com/article/revolut-data-breach-ransom/"},{"credibility":1,"name":"Hackers demand Revolut hand over $3m ransom amid data breach","type":"news_article","url":"https://www.irishtimes.com/business/2026/09/17/hackers-demand-revolut-hand-over-3m-ransom-amid-data-breach/"},{"credibility":2,"name":"Revolut Hackers Lower Ransom to $3M in Monero with 24-Hour Deadline","type":"news_article","url":"https://www.kucoin.com/news/flash/revolut-hackers-lower-ransom-to-3m-in-monero-with-24-hour-deadline"}]},{"content":"Revolut reported the incident to law enforcement and relevant financial regulators. The UK's Information Commissioner's Office (ICO) confirmed it received a report about the breach and was assessing the information provided, according to reporting by the Financial Times and MLex. Italian authorities also reportedly opened a separate investigation into the alleged misuse and compromise of the Italian government PEC email system. Revolut's primary EU banking entity operates under a Lithuanian banking license held by Revolut Bank UAB; Lithuania's State Data Protection Inspectorate has jurisdiction over GDPR compliance for the EU entity and was reported as a likely recipient of a mandatory breach notification. Key regulatory questions under scrutiny include whether Revolut applied adequate requester verification before disclosing sensitive personal data and whether the data released was proportionate under GDPR Article 5 data minimization principles. As of the date of this investigation, no fines or formal enforcement actions have been publicly announced by any regulatory authority.","heading":"Regulatory and Law Enforcement Response","severity":"medium","sources":[{"credibility":1,"name":"Revolut data breach report being assessed by UK's data protection watchdog","type":"regulatory","url":"https://www.mlex.com/mlex/data-privacy-security/articles/2525511"},{"credibility":2,"name":"Revolut KYC Data Breach: When The Bank Knew Its Customer But Not The Requester","type":"news_article","url":"https://fintelegram.com/revolut-kyc-paradox-know-your-requester-government-data-request/"},{"credibility":2,"name":"Revolut Data Breach: Five Days On, What Do We Actually Know?","type":"research","url":"https://cybelangel.com/blog/revolut-data-breach-what-we-know/"},{"credibility":2,"name":"Revolut Leak: Italy Probes Hacked Government PEC Email","type":"news_article","url":"https://financefeeds.com/italy-investigates-government-email-breach-linked-to-revolut-data-leak/"}]},{"content":"Revolut has maintained throughout public communications that this incident does not represent a compromise of its own systems or platform security. The company characterized it as a social engineering attack exploiting the government data-request process and has stated that customer funds remain unaffected. Security researchers have largely corroborated that Revolut's internal infrastructure was not directly breached, while noting that the procedural failure — relying solely on email authentication to validate law-enforcement requests — reflects a significant gap in data-request verification controls. Revolut is not a first-time subject of data security scrutiny: the company suffered a separate data breach in September 2022 in which an attacker used social engineering against an employee to access the personal data of approximately 50,150 customers globally. Lithuania's State Data Protection Inspectorate opened a formal investigation into the 2022 breach. The 2026 incident raises questions about whether procedural controls for government data requests were adequately hardened following the 2022 episode.","heading":"Revolut's Position and Prior Breach History","severity":"medium","sources":[{"credibility":1,"name":"Revolut confirms customer data breach through fake government requests","type":"news_article","url":"https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/"},{"credibility":2,"name":"Revolut Data Breach: How Fake Government Requests Exposed Sensitive Customer Information","type":"news_article","url":"https://cyberone.security/blog/revolut-data-breach-how-fake-government-requests-exposed-sensitive-customer-information"},{"credibility":2,"name":"Revolut (Wikipedia)","type":"other","url":"https://en.wikipedia.org/wiki/Revolut"}]}],"sources_used":[{"credibility":1,"name":"Revolut confirms customer data breach through fake government requests","type":"news_article","url":"https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/"},{"credibility":2,"name":"Revolut says customer KYC, Bitcoin transaction data exposed after fake request from gov't domain","type":"news_article","url":"https://www.theblock.co/news/business/2026-09-12-revolut-says-customer-kyc-bitcoin-transaction-data-exposed-after-fake-request-from-govt-domain-414516"},{"credibility":2,"name":"Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks","type":"news_article","url":"https://securityaffairs.com/198922/data-breach/revolut-exposed-kyc-data-after-fraudulent-government-email-passed-security-checks.html"},{"credibility":2,"name":"Revolut Data Leak May Trace Back to Compromised Italian Government Accounts","type":"news_article","url":"https://securityaffairs.com/199180/data-breach/revolut-data-leak-may-trace-back-to-compromised-italian-government-accounts.html"},{"credibility":2,"name":"Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom","type":"news_article","url":"https://www.securityweek.com/revolut-data-breach-5-months-680-high-profile-accounts-3m-ransom/"},{"credibility":1,"name":"Hackers say they breached Italian state email to target Revolut 'crypto whales'","type":"news_article","url":"https://www.irishtimes.com/business/2026/09/16/hackers-say-they-breached-italian-state-email-to-target-revolut-crypto-whales/"},{"credibility":1,"name":"Hackers demand Revolut hand over $3m ransom amid data breach","type":"news_article","url":"https://www.irishtimes.com/business/2026/09/17/hackers-demand-revolut-hand-over-3m-ransom-amid-data-breach/"},{"credibility":2,"name":"Revolut Hackers Demand $3M Monero Ransom, Threaten to Sell Customer Data","type":"news_article","url":"https://decrypt.co/378472/revolut-hackers-demand-3m-monero-ransom-threaten-to-sell-customer-data-report"},{"credibility":2,"name":"Revolut hackers used infostealer to hijack Italian government emails","type":"news_article","url":"https://cyberinsider.com/revolut-hackers-used-infostealer-to-hijack-italian-government-emails/"},{"credibility":2,"name":"Revolut Hackers Used Infostealers for Elaborate Social Engineering","type":"news_article","url":"https://www.infostealers.com/article/revolut-hackers-used-infostealers-for-elaborate-social-engineering/"},{"credibility":1,"name":"Revolut data breach report being assessed by UK's data protection watchdog","type":"regulatory","url":"https://www.mlex.com/mlex/data-privacy-security/articles/2525511"},{"credibility":2,"name":"Revolut Leak: Italy Probes Hacked Government PEC Email","type":"news_article","url":"https://financefeeds.com/italy-investigates-government-email-breach-linked-to-revolut-data-leak/"},{"credibility":2,"name":"Revolut KYC Data Breach: When The Bank Knew Its Customer But Not The Requester","type":"news_article","url":"https://fintelegram.com/revolut-kyc-paradox-know-your-requester-government-data-request/"},{"credibility":2,"name":"Revolut Data Breach: Five Days On, What Do We Actually Know?","type":"research","url":"https://cybelangel.com/blog/revolut-data-breach-what-we-know/"},{"credibility":2,"name":"Revolut hit with $3 million Monero ransom demand","type":"news_article","url":"https://betanews.com/article/revolut-data-breach-ransom/"},{"credibility":2,"name":"Revolut Handed Over Bitcoin Histories, Passports on Spoofed Government Email","type":"news_article","url":"https://www.cryptotimes.io/2026/09/12/revolut-handed-over-bitcoin-histories-passports-on-spoofed-government-email/"},{"credibility":2,"name":"Revolut Data Breach: Fake Government Email Exposed KYC","type":"news_article","url":"https://cryptonewsbytes.com/revolut-handed-passports-and-bitcoin-records-to-fake-government-request-here-is-everything-we-know/"}],"summary":"On September 12, 2026, Revolut confirmed that an unauthorized third party had obtained sensitive data belonging to approximately 680 customers by submitting fraudulent information requests from a compromised email account operating inside Italy's Ministry of the Interior domain (pec.interno.it), which passed SPF, DKIM, and DMARC authentication checks. The exposed data reportedly included passport copies, identity verification selfies, IBANs, account statements, and full Bitcoin transaction histories. Revolut stated that its own systems and customer funds were not compromised, characterizing the incident as a social engineering attack against its data-request verification procedures rather than an intrusion.","timeline":[{"date":"2026-04-01","event":"Approximate start of the fraudulent data request campaign, based on reporting that the operation ran for approximately five months before discovery. The attackers allegedly used a compromised pec.interno.it email account to submit fraudulent law enforcement requests to Revolut Bank UAB.","source":"SecurityWeek","source_url":"https://www.securityweek.com/revolut-data-breach-5-months-680-high-profile-accounts-3m-ransom/"},{"date":"2026-09-11","event":"Affected Revolut customers began receiving breach notification emails disclosing that their personal and financial data may have been shared with an unauthorized third party.","source":"TechCrunch","source_url":"https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/"},{"date":"2026-09-12","event":"Revolut publicly confirmed the breach to TechCrunch and other outlets, describing 'a sophisticated external impersonation scam' using a legitimate government agency email domain. ZachXBT flagged the customer notification on the same day and assessed it as a targeted high-net-worth operation.","source":"TechCrunch / The Block","source_url":"https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/"},{"date":"2026-09-16","event":"The threat actor group 'iamnotavillain' posted a public extortion demand of 6,000 Monero (approximately $3 million) with a 24-hour deadline, threatening to sell the stolen customer records. The group disclosed using blockchain analysis to select the 680 targeted high-net-worth accounts.","source":"Decrypt / Irish Times","source_url":"https://decrypt.co/378472/revolut-hackers-demand-3m-monero-ransom-threaten-to-sell-customer-data-report"},{"date":"2026-09-16","event":"Additional reporting identified the compromised email account as associated with the pec.interno.it domain (Italy's Ministry of the Interior PEC system), specifically the Prefecture of Reggio Calabria. Hackers also claimed to have extracted 147GB of data from Italian law enforcement systems.","source":"Irish Times / Security Affairs","source_url":"https://www.irishtimes.com/business/2026/09/16/hackers-say-they-breached-italian-state-email-to-target-revolut-crypto-whales/"},{"date":"2026-09-17","event":"Revolut stated it had 'not received any direct contact or demand' from the actors behind the extortion claims. The UK Information Commissioner's Office confirmed it had received a breach report and was assessing the matter.","source":"Irish Times / MLex","source_url":"https://www.irishtimes.com/business/2026/09/17/hackers-demand-revolut-hand-over-3m-ransom-amid-data-breach/"},{"date":"2026-09-17","event":"Cybersecurity firm Hudson Rock reported approximately 300 compromised pec.interno.it webmail credentials in its database, suggesting the attackers obtained access via infostealer-harvested credentials rather than directly targeting government employees.","source":"SecurityWeek / CyberInsider","source_url":"https://cyberinsider.com/revolut-hackers-used-infostealer-to-hijack-italian-government-emails/"}]},"v":1}