
Inside the Revolut data disclosure incident


Prayukth K V
This report assesses a fraudulent emergency data request incident involving Revolut, where customer information was disclosed through abuse of a legitimate government-agency email channel rather than a direct compromise of Revolut systems. The analysis focuses on the attack path, exposed data categories, control failures, detection opportunities, and defensive measures for financial institutions handling law-enforcement requests.
Overview
Between September 11 and September 12, 2026, global fintech giant Revolut (valued at $115 billion with over 80 million customers) experienced a targeted security incident resulting in the unauthorized disclosure of full Know Your Customer (KYC) dossiers and financial transaction histories for 680 high-value customers.
Crucially, no Revolut databases, endpoints, core banking systems, or customer funds were compromised or intruded upon. Public reporting has not identified a direct compromise of Revolut's core banking infrastructure or customer funds. The incident instead involved unauthorized disclosure of customer information through a legitimate communication and compliance channel.
The incident represents a Fraudulent Emergency Data Request (EDR) basically a business logic and social-engineering attack against Revolut’s law enforcement intake process.
An adversary utilized a legitimate, authenticated government email account belonging to an Italian government agency (pec.interno.it) to submit emergency law enforcement requests. Because the inbound requests passed technical domain authentication checks (SPF, DKIM, DMARC), Revolut compliance staff fulfilled the requests in good faith.
The requests originated from a legitimate government-agency email domain, allowing the messages to appear authentic within Revolut's existing law-enforcement intake process. Public reporting does not establish the exact SPF, DKIM and DMARC results for the individual messages, so those authentication outcomes should not be treated as independently confirmed.
The adversary subsequently initiated an extortion campaign under the handle "Revolut Smilik", demanding 10,000 Bitcoin (an actor using the aliases 'iamnotavillain' and 'Revolut Smilik').
Incident chronology and reconstruction

Event timeline
Date | Event | Status |
June 15, 2026 | CERT-AgID reports more than 650 PEC-related abuse events since January 2026 | CONFIRMED |
Prior to Sept. 12 | Fraudulent requests were submitted to Revolut using a legitimate government-agency email domain | CONFIRMED |
Sept. 12 | Revolut publicly confirms unauthorized disclosure of customer information following fraudulent requests | CONFIRMED |
Sept. 12 onward | Affected customers are notified | CONFIRMED |
Sept. 14–15 | KELA analyses extortion infrastructure and identifies public repository/commit artifacts | CONFIRMED |
Sept. 15–17 | Reporting identifies approximately 680 affected customers and continuing extortion claims | CONFIRMED |
Sept. 16–17 | Reporting indicates a $3m Monero demand; Revolut says it has not received a direct ransom demand | REPORTED / CONTESTED |
Affected assets and infrastructure
Asset / Process | Current Assessment |
Law-enforcement / legal-request intake process | Abused / exploited |
Customer identity information | Disclosed to unauthorized party |
Identity documents | Reportedly disclosed |
Verification selfies | Reportedly potentially disclosed |
Account statements / transaction histories | Reportedly potentially disclosed |
Revolut core systems | No evidence of direct compromise reported |
Customer funds | Reportedly unaffected |
Customer passwords | No evidence of compromise reported |
IAM / internal authentication infrastructure | Not publicly established |
Cloud infrastructure | Not publicly established |
Data compromise analysis
The compromise resulted in the exfiltration of complete, unredacted customer identity dossiers.
Exposed Data Types: Full legal names, dates of birth, telephone numbers, postal addresses, email addresses, passport copies, driver's licenses, onboarding verification selfies, account statements, IBANs, and complete transaction histories (including on-chain Bitcoin deposit/withdrawal wallet addresses).
Exposed information may have included:
Full names
Dates of birth
Addresses
Email addresses
Telephone numbers
Passport / identity-document copies
Verification selfies
Account statements
Transaction histories
IBAN/account information
Cryptocurrency transaction information
Exclusion List: Raw biometric facial telemetry models, payment card numbers, CVVs, account PINs, and portal passwords were not disclosed.
Victim Count: Exactly 680 individuals.
Victim Profile: Highly targeted toward High-Net-Worth (HNW) crypto holders and technology executives. Confirmed victims include former Mt. Gox CEO Mark Karpelès and Gamdom CEO Felix Römer.
Threat actor attribution and technical profiling

Attribution assessment
Claimant: A threat actor/group operating under the name "Revolut Smilik" (previously using Telegram handle "iamnotavillain").
Ransom Demand: 10,000 BTC (~$600M+ USD). It has to be noted that the threat actor publicly demanded approximately $3 million in Monero (XMR), according to Financial Times reporting. Revolut has stated that it has not received direct contact or a direct ransom demand from the alleged attackers.
Forensic infrastructure analysis
Extortion Hosting: Static page hosted on GitHub Pages (btres9kijob[.]github.io) pointing to imnotavillain[.]xyz.
Build Timeline: Assembled in ~6.5 hours on September 14, 2026, entirely via web interface.
Operational Flaws (OPSEC Failures):
Email Exposure: Public Git commit logs revealed an Outlook.com author email address.
Timezone Indicator: Commits contained a UTC-07:00 offset.
File Recovery: Deleted assets (proof.jpg, jurisdiction.jpg, Screenshot_35.jpg) were recoverable directly from Git commit history.
Initial access vector analysis
Compromised Identity: Italian Government Certified Electronic Mail (Posta Elettronica Certificata - PEC) account under domain pec.interno.it (associated with the Prefecture of Reggio Calabria).
Context: In June 2026, Italy's CERT-AgID reported widespread credential theft via infostealer malware affecting over 650 PEC accounts.
MITRE ATT&CK mapping
Technique ID | Technique Name | Operational Evidence | Confidence | Status |
T1566.001 | Phishing: Spearphishing Attachment / Link | Use of forged legal demand documentation attached to emergency data requests sent to compliance intake desks. | High | [CONFIRMED] |
T1078.004 | Valid Accounts: Cloud Accounts | Leveraging an authentic government agency PEC mailbox (pec.interno.it) to pass external email filters. | High | [CONFIRMED] |
T1199 | Trusted Relationship | Exploiting established trust frameworks between law enforcement authorities and regulated financial institutions. | High | [CONFIRMED] |
T1020 | Automated Exfiltration | Requesting and receiving compiled KYC data bundles via structured email communications. | High | [CONFIRMED] |
T1486 | Data Encrypted for Impact | Threatening public release of confidential data unless ransom is paid (Extortion/Double Extortion). | High | [CONFIRMED] |
T1589.002 | Gather Victim Identity Information: Email Addresses | Reconnaissance targeting specific HNW accounts and identifying deposit addresses prior to submitting EDR requests. | Medium | [ASSESSED] |
Attack-chain reconstruction
│
▼
[STAGE 1: UPSTREAM INFRASTRUCTURE COMPROMISE]
Actor gains control of valid Italian Government PEC mailbox (pec.interno.it)
via infostealer logs or secondary credential markets.
│
▼
[STAGE 2: RECONNAISSANCE & TARGET SELECTION]
Actor compiles a list of 680 HNW crypto users, obtaining specific target
identifiers (e.g., target names, wallet addresses, IBANs).
│
▼
[STAGE 3: EDR FABRICATION & TRANSMISSION]
Actor crafts Emergency Data Requests with fake urgent legal headers and
sends them via the authenticated PEC mailbox to Revolut's legal team.
│
▼
[STAGE 4: COMPLIANCE INTAKE & VERIFICATION BYPASS]
Revolut automated systems check SPF/DKIM/DMARC -> PASS.
Staff perform manual review, observe legitimate domain, and bypass OOB callback.
│
▼
[STAGE 5: DOSSIER COMPILATION & DISCLOSURE]
Compliance operator extracts KYC records (passports, selfies, transaction logs)
and replies directly to the requester's email.
│
▼
[STAGE 6: EXTORTION & PUBLIC DISCLOSURE]
Actor sets up extortion site (imnotavillain[.]xyz), leaks sample dossiers,
and demands 10,000 BTC.
Technically unusual and under-discussed vulnerabilities
The Fallacy of Domain Authentication as Authorization
Email authentication protocols (SPF, DKIM, DMARC) confirm that a message originated from an authorized server for a given domain. They provide zero guarantee regarding the identity or intent of the human operator behind the keyboard. Revolut’s intake controls relied on technical domain validity as a proxy for legal authority.
PEC System Architecture Blind Spot
Italy’s Certified Electronic Mail (Posta Elettronica Certificata - PEC) provides legal proof of sending and delivery. However, it lacks mandatory Multi-Factor Authentication (MFA) or session-binding controls across all regional municipal nodes. When an adversary gains PEC credentials, they inherit absolute legal authenticity across European legal frameworks.
Exfiltration via Authorized Compliance Channels
Traditional Endpoint Detection & Response (EDR), Data Loss Prevention (DLP), and User and Entity Behavior Analytics (UEBA) are configured to detect unauthorized network exfiltration, database dumps, or unknown C2 protocols. In this case, exfiltration occurred over standard corporate email, initiated by authorized compliance personnel performing routine duties, rendering technical security stacks completely blind.
KYC Dossiers as Tactical "Physical Targeting Dossiers": For cryptocurrency investors, the joining of pseudonymous on-chain deposit addresses with real-world home addresses, passport numbers, and phone numbers elevates physical security risks (such as home invasions, forced transfer extortion, SIM swaps).
Adversarial enabling conditions
Validated Access Point: Possession of an active credential for a valid government domain (pec.interno.it).
Absence of Out-of-Band (OOB) Verification: Fulfilling high-sensitivity data requests without conducting independent voice/phone callbacks using official, independently sourced government directory numbers.
Single-Operator Approval Vulnerability: Lack of dual-authorization requirements ("four-eyes principle") prior to exporting and transmitting full customer KYC packages.
Control and defensive failures
Identity and Verification Control Failure: Automated systems validated domain headers, but no secondary verification was enforced to validate the human sender’s authorization.
Data Minimization Deficit: Upon accepting the emergency request, compliance staff exported full transaction histories, IBANs, and selfie images. Emergency disclosures should be strictly bounded to minimum necessary records.
SIEM / Anomaly Detection Gap: Security Operations Centers typically do not monitor compliance intake queues for abnormal spikes in EDR volumes targeting specific HNW user cohorts.
Detection opportunities and telemetry requirements
Detection Opportunity | Required Telemetry | Proposed Detection Logic / Rule | MITRE ID |
Abnormal Outbound Attachment Volume from Compliance | Email Gateway / DLP Logs | Alert when a single compliance endpoint emails >10 PDF/ZIP attachments containing identity terms (passport, selfie, KYC) to external domains within 1 hour. | T1020 |
Unverified EDR High-Value Target Match | Compliance CRM / EDR Log Telemetry | Cross-reference incoming EDR user IDs against internal High-Net-Worth / VIP customer tags. Alert on statistically anomalous outbound disclosure volume from compliance personnel relative to individual and team baselines. Examples include unusually large number of KYC attachments unusually large aggregate data volume unusual recipient domains unusual geographic/legal jurisdiction multiple requests targeting VIP customers repeated requests originating from a single government mailbox unusual request-to-disclosure time multiple disclosures outside normal business patterns | T1589 |
Anomalous Law Enforcement Domain Activity | Mail Gateway / Header Analysis | Flag inbound legal demands originating from foreign government domains that lack an active Mutual Legal Assistance Treaty (MLAT) or European Investigation Order (EIO) case mapping. | T1199 |
Broader cybersecurity implications
Systemic Weaponization of the EDR Mechanism: This incident aligns with warnings issued in FBI Private Industry Notification 20241104-001, highlighting that threat actors routinely acquire government mailboxes to issue fraudulent subpoenas and emergency requests.
Obsoletion of Perimeter-Centric Email Security: Traditional email security relies on domain legitimacy. Security architectures must transition toward zero-trust intake models where domain validity carries zero implicit authorization trust.
Actionable defensive playbook

Immediate Actions (0–30 Days)
Mandatory Out-of-Band (OOB) Verification: Prohibit email-only fulfilment of Emergency Data Requests. Compliance operators must verify requests by calling the relevant agency via official, independently sourced switchboard numbers.
Dual-Control Authorization ("Four-Eyes Principle"): Require secondary supervisor sign-off before releasing raw KYC artifacts, transaction logs, or identity documents.
Near-Term Actions (30–90 Days)
DLP Bounding on Compliance Outbound Email: Configure DLP rules to block direct emailing of unencrypted identity document packages (.pdf, .png, .jpg containing identity keywords). Require data delivery via secure, authenticated download portals with audit logging.
Granular Data Minimization Filters: Lower limits on EDR response packages. Implement granular disclosure policies that release only the minimum data necessary for the validated legal basis and stated emergency purpose. Full transaction histories and sensitive identity artifacts should require additional authorization and documented justification where legally permissible.
Strategic Actions (90+ Days)
Transition to Authenticated LER Portals: Deprecate direct email intake for legal demands. Transition to authenticated portal architectures requiring law enforcement agency identity federation and digital signature verification.
Requester authentication
Verify:
Agency
Individual investigator
Official role
Case/reference number
Legal authority
Emergency justification
Requested data scope
Requested delivery mechanism
Only then approve disclosure.
Sources
Financial Times: "Revolut handed nearly 700 customers' data to scammers" (Sept 16, 2026).
KELA Cyber Intelligence Center: "Revolut Data Breach: Tracing the Extortion Site Infrastructure"(Sept 15, 2026).
City AM: "Revolut hackers stole nearly 700 customers' private data" (Sept 15, 2026).
Security Affairs: "Revolut Data Leak May Trace Back to Compromised Italian Government Accounts"(Sept 16, 2026).
FBI Private Industry Notification: PIN 20241104-001 (Compromised Government Email Accounts Used to Issue Fraudulent Emergency Data Requests).
ZachXBT Public Disclosures: On-chain investigation and breach notification surfacing (Sept 12, 2026).
Shieldworkz assessment

What We Know: Revolut compliance staff released complete identity dossiers for 680 high-value customers after receiving fraudulent EDRs from an authenticated Italian government mailbox (pec.interno.it). Revolut’s core banking networks were never breached.
What We Probably Know: The adversary pre-selected specific HNW targets based on prior on-chain telemetry, using the EDR mechanism to unmask pseudonymous crypto addresses into physical identity packages.
What Remains Unconfirmed: The exact identity of the "Revolut Smilik" threat actors, and whether other regulated financial institutions received identical requests from the same compromised PEC mailbox.
Cryptographic email authentication is not an authorization mechanism. SPF, DKIM and DMARC can provide evidence that a message is associated with an authorized domain or sending infrastructure, but they do not establish that the individual operating the mailbox is authorized to issue a legal request, that the mailbox has not been compromised, or that the requested disclosure is valid.
The Revolut incident demonstrates that legal, compliance and trust workflows must be treated as part of the enterprise attack surface. An attacker does not always need to penetrate a database when the organization itself can be induced to retrieve and disclose the database contents through a trusted process.
Alleged Cyberattack and U.S. Investigation of VLCC VL Prosperity
Shieldworkz regulatory playbook
Wöchentlich erhalten
Ressourcen & Nachrichten
Erfahren Sie, wie unsere branchenführenden OT-Security-Lösungen kritische Sicherheitsherausforderungen gemäß KRITIS-Anforderungen bewältigen
Dies könnte Ihnen auch gefallen.

Investigative cyber threat research report: Cyberattacks on U.S.-bound energy tankers

Team Shieldworkz

The OT Lull: What a 30-day decline in direct intrusion activity actually tells us

Prayukth K V

NERC CIP Compliance Software: 9 Capabilities Utilities Should Compare

Team Shieldworkz

Investigative Cyber Threat Research Report: Alleged Cyberattack and U.S. Investigation of VLCC VL Prosperity

Prayukth K V

Central Electricity Authority Cyber Security Regulations: Complete Guide

Team Shieldworkz

Inside the Kimberly-Clark / ShinyHunters Incident

Team Shieldworkz

