Security1 publisher3 min readPublished
Forged government requests pulled passport data out of Revolut for five months
A hacker used a government employee's infostealer-compromised mailbox to send fraudulent requests to Revolut's Lithuanian subsidiary for about five months, and roughly 680 customers' passports and financial data went out.
The Watch · Security desk

What happened
- SecurityWeek understands roughly 680 Revolut customers, reportedly cryptocurrency whales, had personal and financial information taken.
- A threat actor using the moniker IAmNotAVillain demanded $3 million publicly on Wednesday and threatened to sell the customer data.
- The hackers separately claimed a six-month campaign that also took more than 147GB of data from an Italian law enforcement agency.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure With over 300 pec.interno.it credentials circulating in infostealer logs, anyone who buys a log can send mail that clears a sender-address check at any institution that answers Italian government requests.
- constraint The legal duty to answer law enforcement leaves a regulated firm one option for closing this hole: verify the requester out of band. That adds delay to every genuine request too.
- contradiction Duration and scope currently rest on the actor's own account, five months in one telling and six in another, while the company has yet to confirm the count or the agency.
- decision Revolut says it has had no contact from the claimants, so the $3 million is a resale threat aimed at buyers.
More than 300 compromised credentials tied to pec.interno.it, the certified-mail domain of the Italian Ministry of the Interior, are already sitting in infostealer logs, according to Hudson Rock [16]. The compromised address on that domain appears to belong to a ministry employee [15]. Hudson Rock does not think the actor did the infecting: "Based on this intelligence, we assess that it is highly unlikely the hacker actively infected these specific employees themselves. Instead, they likely purchased or utilized existing Infostealer logs containing these credentials, attempting to obfuscate their true method of initial access," the firm wrote [17].
Hudson Rock says the campaign began when the hacker took over a government employee's accounts through an infostealer infection and used the mailbox to send fraudulent government requests to Revolut Bank UAB, the Lithuania-based subsidiary of the British firm [10]. A request arriving from a genuine government address passes the check most legal-request desks actually run. The hacker told the Duel investigations team that Revolut Bank UAB answered without questioning the legitimacy of the requests [11], and that the bank kept answering for roughly five months [9].
What came out, per Revolut's own notification to potentially affected users last week, was personal information, passports, email addresses, phone numbers and financial information [2]. Passwords can be changed after a breach; passport numbers stay with the customer.
SecurityWeek understands about 680 Revolut customers were affected, reportedly cryptocurrency whales [12]. Set that against the $3 million publicly demanded by a threat actor using the moniker IAmNotAVillain, who posted the demand on Wednesday and threatened to sell the data [5]. The demand works out to roughly $4,400 per account [18].
The demand exists as a public post. "Revolut has not received any direct contact or demand from the individuals or group making these claims," a Revolut spokesperson said [7]. It appears the actor has not approached the company directly [6]. IAmNotAVillain also said publicly that a sample of the stolen data is held by a former associate who also claims responsibility for the breach [8]. Revolut did not name the impersonated agency or the number of people affected when SecurityWeek asked [4].
The duration comes from the actor, and the actor has given two figures. In one account the campaign ran five months [9]; in separate communications the hackers put it at six and added the theft of more than 147GB of data from an Italian law enforcement agency [13]. Italian police have opened an investigation [14].
The control that failed here was a look at the sender address. Revolut is required to respond to law enforcement legal requests, and it complied [3]. Any other firm under that duty is checking the same address, on a domain whose credentials are for sale in bulk.
What to watch
- Whether Revolut confirms the number of affected individuals and names the impersonated agency it declined to identify to SecurityWeek.
- Whether the sample IAmNotAVillain says is held by a former associate appears for sale. A sale would put a second party in possession of the 680 records.
- What the Italian police investigation establishes about the claimed 147GB taken from a law enforcement agency.