Skip to content

Invest1 publisher3 min readPublished

A compromised government email account pulled about 680 customer files out of Revolut over months

Revolut answered fraudulent information requests sent from a real government email account for months. A group calling itself iamnotavillain now wants about $3 million in Monero for the roughly 680 customer files.

The Investor · Invest desk

Photograph accompanying A compromised government email account pulled about 680 customer files out of Revolut over months
Photo: americanbanker.com

What happened

  • Revolut disclosed on 12 September 2026 that an unauthorized party had used an email account on a genuine government-agency domain to send it fraudulent information requests.
  • The bank treated those messages as official legal demands and supplied customer records in response over a period of months before the deception was identified.
  • A source familiar with the matter put the affected population at roughly 680 customers, many of them selected because of suspected cryptocurrency activity, out of tens of millions of users.
  • A group calling itself iamnotavillain demanded about $3 million in Monero within 24 hours, and a Revolut spokesperson told Reuters the bank had received no direct contact or demand from it.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost The demand comes to roughly $4,400 for each of about 680 customers, a per-head price for files the group already holds, with the funds untouched and the systems intact.
  • constraint Revolut cannot close this hole by declining law-enforcement requests, because regulated firms must answer legitimate ones; the only place left to add a check is the demand itself, and that slows every response.
  • exposure Customers whose identity documents and Bitcoin histories were handed over face targeted fraud and further extortion attempts, and that risk survives whatever the bank pays.
  • precedent Both the group and the bank say there was no private contact before the public countdown, so the pressure was applied through the press and the customers; any firm with a legal-request inbox is reachable the same way.

The control that failed is the one that reads a legal demand and decides whether the authority behind it is real. Revolut's checks looked at the sender, and the sender was an email account on a genuine government-agency domain [2]. The messages passed as official legal demands and the bank answered them over a period of months [3]. The duration matters more than the first request: the queue kept answering one address for months, and the check it ran each time stopped at the sender [15].

Roughly 680 customers were affected, according to a person familiar with the matter [4], and the public demand was about $3 million in Monero inside 24 hours [7]: about $4,400 a customer [20]. Revolut says no funds were taken and that its systems, databases and customer accounts were not penetrated [6][5]. The $3 million buys a promise not to resell the files to other criminal groups [7].

Many of the accounts appear to have been picked because of suspected cryptocurrency activity [8]. The group told the Financial Times it chose targets through blockchain analysis and had used a compromised Italian government email system to pose as law enforcement [10]. The material that left the company included passport and driving licence copies, verification photographs, IBANs and transaction histories with Bitcoin activity [9]. Per the report, the practical danger for those customers is targeted fraud or further extortion attempts, and that danger sits outside whatever Revolut decides about the payment [19].

The report points to how financial firms check the substance of legal demands even when the sending infrastructure looks genuine [16]. Regulated firms have to answer legitimate government and law-enforcement requests [14]. That leaves one place to add a check: an out-of-band callback on every demand, paid for in compliance handling time.

If Revolut pays nothing and the records circulate, the cost falls on those 680 people and on the Italian authorities now examining the compromise of the government email accounts [17]. The regulators the bank notified itself, data-protection authorities and financial supervisors among them [13], could instead treat a months-long response window as a control failure. Then the number stops being $3 million and becomes whatever they assess. A third possibility is that the group holds less than it says.

In my view the supervisory question is the more expensive one. The money named in the public countdown is $3 million [7], while the response window the bank has already reported to its own regulators is measured in months [3][13]. A supervisory finding that answering an authenticated government domain met the standard of care would prove that wrong. It would move the failure onto Italy's compromised email accounts [17].

What to watch

  • Whether Italian investigators identify other banks and payment firms that answered requests from the same compromised accounts.
  • Whether Revolut's affected-customer total stays near 680 once the full history of fraudulent requests is reconstructed.
  • Whether any of the files surface for sale, which would be the first independent test of the group's claim to hold them.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories