site-logo
site-logo
site-logo

Inside the Revolut data disclosure incident

Inside the Revolut data disclosure incident

Inside the Revolut data disclosure incident

Revolut cyberattack
author

Prayukth K V

This report assesses a fraudulent emergency data request incident involving Revolut, where customer information was disclosed through abuse of a legitimate government-agency email channel rather than a direct compromise of Revolut systems. The analysis focuses on the attack path, exposed data categories, control failures, detection opportunities, and defensive measures for financial institutions handling law-enforcement requests.

Overview

Between September 11 and September 12, 2026, global fintech giant Revolut (valued at $115 billion with over 80 million customers) experienced a targeted security incident resulting in the unauthorized disclosure of full Know Your Customer (KYC) dossiers and financial transaction histories for 680 high-value customers.

Crucially, no Revolut databases, endpoints, core banking systems, or customer funds were compromised or intruded upon. Public reporting has not identified a direct compromise of Revolut's core banking infrastructure or customer funds. The incident instead involved unauthorized disclosure of customer information through a legitimate communication and compliance channel.

The incident represents a Fraudulent Emergency Data Request (EDR) basically a business logic and social-engineering attack against Revolut’s law enforcement intake process.

An adversary utilized a legitimate, authenticated government email account belonging to an Italian government agency (pec.interno.it) to submit emergency law enforcement requests. Because the inbound requests passed technical domain authentication checks (SPF, DKIM, DMARC), Revolut compliance staff fulfilled the requests in good faith.

The requests originated from a legitimate government-agency email domain, allowing the messages to appear authentic within Revolut's existing law-enforcement intake process. Public reporting does not establish the exact SPF, DKIM and DMARC results for the individual messages, so those authentication outcomes should not be treated as independently confirmed.

The adversary subsequently initiated an extortion campaign under the handle "Revolut Smilik", demanding 10,000 Bitcoin (an actor using the aliases 'iamnotavillain' and 'Revolut Smilik').

Incident chronology and reconstruction


 

Event timeline

Date

Event

Status

June 15, 2026

CERT-AgID reports more than 650 PEC-related abuse events since January 2026

CONFIRMED

Prior to Sept. 12

Fraudulent requests were submitted to Revolut using a legitimate government-agency email domain

CONFIRMED

Sept. 12

Revolut publicly confirms unauthorized disclosure of customer information following fraudulent requests

CONFIRMED

Sept. 12 onward

Affected customers are notified

CONFIRMED

Sept. 14–15

KELA analyses extortion infrastructure and identifies public repository/commit artifacts

CONFIRMED

Sept. 15–17

Reporting identifies approximately 680 affected customers and continuing extortion claims

CONFIRMED

Sept. 16–17

Reporting indicates a $3m Monero demand; Revolut says it has not received a direct ransom demand

REPORTED / CONTESTED


Affected assets and infrastructure

Asset / Process

Current Assessment

Law-enforcement / legal-request intake process

Abused / exploited

Customer identity information

Disclosed to unauthorized party

Identity documents

Reportedly disclosed

Verification selfies

Reportedly potentially disclosed

Account statements / transaction histories

Reportedly potentially disclosed

Revolut core systems

No evidence of direct compromise reported

Customer funds

Reportedly unaffected

Customer passwords

No evidence of compromise reported

IAM / internal authentication infrastructure

Not publicly established

Cloud infrastructure

Not publicly established

Data compromise analysis

The compromise resulted in the exfiltration of complete, unredacted customer identity dossiers.

  • Exposed Data Types: Full legal names, dates of birth, telephone numbers, postal addresses, email addresses, passport copies, driver's licenses, onboarding verification selfies, account statements, IBANs, and complete transaction histories (including on-chain Bitcoin deposit/withdrawal wallet addresses).

Exposed information may have included:

  • Full names

  • Dates of birth

  • Addresses

  • Email addresses

  • Telephone numbers

  • Passport / identity-document copies

  • Verification selfies

  • Account statements

  • Transaction histories

  • IBAN/account information

  • Cryptocurrency transaction information

  • Exclusion List: Raw biometric facial telemetry models, payment card numbers, CVVs, account PINs, and portal passwords were not disclosed.

  • Victim Count: Exactly 680 individuals.

  • Victim Profile: Highly targeted toward High-Net-Worth (HNW) crypto holders and technology executives. Confirmed victims include former Mt. Gox CEO Mark Karpelès and Gamdom CEO Felix Römer.

 Threat actor attribution and technical profiling

 

Attribution assessment

  • Claimant: A threat actor/group operating under the name "Revolut Smilik" (previously using Telegram handle "iamnotavillain").

  • Ransom Demand: 10,000 BTC (~$600M+ USD). It has to be noted that the threat actor publicly demanded approximately $3 million in Monero (XMR), according to Financial Times reporting. Revolut has stated that it has not received direct contact or a direct ransom demand from the alleged attackers.

Forensic infrastructure analysis  

  • Extortion Hosting: Static page hosted on GitHub Pages (btres9kijob[.]github.io) pointing to imnotavillain[.]xyz.

  • Build Timeline: Assembled in ~6.5 hours on September 14, 2026, entirely via web interface.

  • Operational Flaws (OPSEC Failures):

    • Email Exposure: Public Git commit logs revealed an Outlook.com author email address.

    • Timezone Indicator: Commits contained a UTC-07:00 offset.

    • File Recovery: Deleted assets (proof.jpg, jurisdiction.jpg, Screenshot_35.jpg) were recoverable directly from Git commit history.

Initial access vector analysis

  • Compromised Identity: Italian Government Certified Electronic Mail (Posta Elettronica Certificata - PEC) account under domain pec.interno.it (associated with the Prefecture of Reggio Calabria).

  • Context: In June 2026, Italy's CERT-AgID reported widespread credential theft via infostealer malware affecting over 650 PEC accounts.

 

MITRE ATT&CK mapping

Technique ID

Technique Name

Operational Evidence

Confidence

Status

T1566.001

Phishing: Spearphishing Attachment / Link

Use of forged legal demand documentation attached to emergency data requests sent to compliance intake desks.

High

[CONFIRMED]

T1078.004

Valid Accounts: Cloud Accounts

Leveraging an authentic government agency PEC mailbox (pec.interno.it) to pass external email filters.

High

[CONFIRMED]

T1199

Trusted Relationship

Exploiting established trust frameworks between law enforcement authorities and regulated financial institutions.

High

[CONFIRMED]

T1020

Automated Exfiltration

Requesting and receiving compiled KYC data bundles via structured email communications.

High

[CONFIRMED]

T1486

Data Encrypted for Impact

Threatening public release of confidential data unless ransom is paid (Extortion/Double Extortion).

High

[CONFIRMED]

T1589.002

Gather Victim Identity Information: Email Addresses

Reconnaissance targeting specific HNW accounts and identifying deposit addresses prior to submitting EDR requests.

Medium

[ASSESSED]

 

Attack-chain reconstruction

                                   │

                                   ▼

 [STAGE 1: UPSTREAM INFRASTRUCTURE COMPROMISE]

 Actor gains control of valid Italian Government PEC mailbox (pec.interno.it)

 via infostealer logs or secondary credential markets.

                                   │

                                   ▼

 [STAGE 2: RECONNAISSANCE & TARGET SELECTION]

 Actor compiles a list of 680 HNW crypto users, obtaining specific target

 identifiers (e.g., target names, wallet addresses, IBANs).

                                   │

                                   ▼

 [STAGE 3: EDR FABRICATION & TRANSMISSION]

 Actor crafts Emergency Data Requests with fake urgent legal headers and

 sends them via the authenticated PEC mailbox to Revolut's legal team.

                                   │

                                   ▼

 [STAGE 4: COMPLIANCE INTAKE & VERIFICATION BYPASS]

 Revolut automated systems check SPF/DKIM/DMARC -> PASS.

 Staff perform manual review, observe legitimate domain, and bypass OOB callback.

                                   │

                                   ▼

 [STAGE 5: DOSSIER COMPILATION & DISCLOSURE]

 Compliance operator extracts KYC records (passports, selfies, transaction logs)

 and replies directly to the requester's email.

                                   │

                                   ▼

 [STAGE 6: EXTORTION & PUBLIC DISCLOSURE]

 Actor sets up extortion site (imnotavillain[.]xyz), leaks sample dossiers,

 and demands 10,000 BTC.

Technically unusual and under-discussed vulnerabilities

  • The Fallacy of Domain Authentication as Authorization

    Email authentication protocols (SPF, DKIM, DMARC) confirm that a message originated from an authorized server for a given domain. They provide zero guarantee regarding the identity or intent of the human operator behind the keyboard. Revolut’s intake controls relied on technical domain validity as a proxy for legal authority.

  • PEC System Architecture Blind Spot

    Italy’s Certified Electronic Mail (Posta Elettronica Certificata - PEC) provides legal proof of sending and delivery. However, it lacks mandatory Multi-Factor Authentication (MFA) or session-binding controls across all regional municipal nodes. When an adversary gains PEC credentials, they inherit absolute legal authenticity across European legal frameworks.

  • Exfiltration via Authorized Compliance Channels

    Traditional Endpoint Detection & Response (EDR), Data Loss Prevention (DLP), and User and Entity Behavior Analytics (UEBA) are configured to detect unauthorized network exfiltration, database dumps, or unknown C2 protocols. In this case, exfiltration occurred over standard corporate email, initiated by authorized compliance personnel performing routine duties, rendering technical security stacks completely blind.

  • KYC Dossiers as Tactical "Physical Targeting Dossiers": For cryptocurrency investors, the joining of pseudonymous on-chain deposit addresses with real-world home addresses, passport numbers, and phone numbers elevates physical security risks (such as home invasions, forced transfer extortion, SIM swaps).

Adversarial enabling conditions

  • Validated Access Point: Possession of an active credential for a valid government domain (pec.interno.it).

  • Absence of Out-of-Band (OOB) Verification: Fulfilling high-sensitivity data requests without conducting independent voice/phone callbacks using official, independently sourced government directory numbers.

  • Single-Operator Approval Vulnerability: Lack of dual-authorization requirements ("four-eyes principle") prior to exporting and transmitting full customer KYC packages.

Control and defensive failures

  • Identity and Verification Control Failure: Automated systems validated domain headers, but no secondary verification was enforced to validate the human sender’s authorization.

  • Data Minimization Deficit: Upon accepting the emergency request, compliance staff exported full transaction histories, IBANs, and selfie images. Emergency disclosures should be strictly bounded to minimum necessary records.

  • SIEM / Anomaly Detection Gap: Security Operations Centers typically do not monitor compliance intake queues for abnormal spikes in EDR volumes targeting specific HNW user cohorts.

 Detection opportunities and telemetry requirements

Detection Opportunity

Required Telemetry

Proposed Detection Logic / Rule

MITRE ID

Abnormal Outbound Attachment Volume from Compliance

Email Gateway / DLP Logs

Alert when a single compliance endpoint emails >10 PDF/ZIP attachments containing identity terms (passport, selfie, KYC) to external domains within 1 hour.

T1020

Unverified EDR High-Value Target Match

Compliance CRM / EDR Log Telemetry

Cross-reference incoming EDR user IDs against internal High-Net-Worth / VIP customer tags. Alert on statistically anomalous outbound disclosure volume from compliance personnel relative to individual and team baselines. Examples include

  unusually large number of KYC attachments

  unusually large aggregate data volume

  unusual recipient domains

  unusual geographic/legal jurisdiction

  multiple requests targeting VIP customers

  repeated requests originating from a single government mailbox

  unusual request-to-disclosure time

  multiple disclosures outside normal business patterns

T1589

Anomalous Law Enforcement Domain Activity

Mail Gateway / Header Analysis

Flag inbound legal demands originating from foreign government domains that lack an active Mutual Legal Assistance Treaty (MLAT) or European Investigation Order (EIO) case mapping.

T1199

Broader cybersecurity implications

  • Systemic Weaponization of the EDR Mechanism: This incident aligns with warnings issued in FBI Private Industry Notification 20241104-001, highlighting that threat actors routinely acquire government mailboxes to issue fraudulent subpoenas and emergency requests.

  • Obsoletion of Perimeter-Centric Email Security: Traditional email security relies on domain legitimacy. Security architectures must transition toward zero-trust intake models where domain validity carries zero implicit authorization trust.

 

Actionable defensive playbook

 

Immediate Actions (0–30 Days)

  • Mandatory Out-of-Band (OOB) Verification: Prohibit email-only fulfilment of Emergency Data Requests. Compliance operators must verify requests by calling the relevant agency via official, independently sourced switchboard numbers.

  • Dual-Control Authorization ("Four-Eyes Principle"): Require secondary supervisor sign-off before releasing raw KYC artifacts, transaction logs, or identity documents.

Near-Term Actions (30–90 Days)

  • DLP Bounding on Compliance Outbound Email: Configure DLP rules to block direct emailing of unencrypted identity document packages (.pdf, .png, .jpg containing identity keywords). Require data delivery via secure, authenticated download portals with audit logging.

  • Granular Data Minimization Filters: Lower limits on EDR response packages. Implement granular disclosure policies that release only the minimum data necessary for the validated legal basis and stated emergency purpose. Full transaction histories and sensitive identity artifacts should require additional authorization and documented justification where legally permissible.

Strategic Actions (90+ Days)

  • Transition to Authenticated LER Portals: Deprecate direct email intake for legal demands. Transition to authenticated portal architectures requiring law enforcement agency identity federation and digital signature verification.

Requester authentication

Verify:

  • Agency

  • Individual investigator

  • Official role

  • Case/reference number

  • Legal authority

  • Emergency justification

  • Requested data scope

  • Requested delivery mechanism

Only then approve disclosure.

Sources

  • Financial Times: "Revolut handed nearly 700 customers' data to scammers" (Sept 16, 2026).

  • KELA Cyber Intelligence Center: "Revolut Data Breach: Tracing the Extortion Site Infrastructure"(Sept 15, 2026).

  • City AM: "Revolut hackers stole nearly 700 customers' private data" (Sept 15, 2026).

  • Security Affairs: "Revolut Data Leak May Trace Back to Compromised Italian Government Accounts"(Sept 16, 2026).

  • FBI Private Industry Notification: PIN 20241104-001 (Compromised Government Email Accounts Used to Issue Fraudulent Emergency Data Requests).

  • ZachXBT Public Disclosures: On-chain investigation and breach notification surfacing (Sept 12, 2026).

 

Shieldworkz assessment

 

  • What We Know: Revolut compliance staff released complete identity dossiers for 680 high-value customers after receiving fraudulent EDRs from an authenticated Italian government mailbox (pec.interno.it). Revolut’s core banking networks were never breached.

  • What We Probably Know: The adversary pre-selected specific HNW targets based on prior on-chain telemetry, using the EDR mechanism to unmask pseudonymous crypto addresses into physical identity packages.

  • What Remains Unconfirmed: The exact identity of the "Revolut Smilik" threat actors, and whether other regulated financial institutions received identical requests from the same compromised PEC mailbox.

  • Cryptographic email authentication is not an authorization mechanism. SPF, DKIM and DMARC can provide evidence that a message is associated with an authorized domain or sending infrastructure, but they do not establish that the individual operating the mailbox is authorized to issue a legal request, that the mailbox has not been compromised, or that the requested disclosure is valid.

The Revolut incident demonstrates that legal, compliance and trust workflows must be treated as part of the enterprise attack surface. An attacker does not always need to penetrate a database when the organization itself can be induced to retrieve and disclose the database contents through a trusted process.

 Alleged Cyberattack and U.S. Investigation of VLCC VL Prosperity

Shieldworkz regulatory playbook

Shielworkz remediation guides

 

 

Get Weekly

Resources & News

See How Our Industry-Leading OT Security Solutions Address Critical Security Challenges

You may also like

BG image

Get Started Now

Scale your CPS security posture

Get in touch with our CPS security experts for a free consultation.

BG image

Get Started Now

Scale your CPS security posture

Get in touch with our CPS security experts for a free consultation.

BG image

Get Started Now

Scale your CPS security posture

Get in touch with our CPS security experts for a free consultation.