Invest2 publishersIndependently confirmed2 min readPublished
Revolut will pay for new IDs after sending 680 customers' data to a hijacked Italian police email
Revolut will pay to replace identity documents for the 680 customers whose data it sent to a hijacked Italian government email address. The bank has not put a price on the pledge, and it disagrees with Italy's interior minister over whose check let the request through.
The Investor · Invest desk

What happened
- The requests came from an address on the Reggio Calabria police email system that had never been used before, Interior Minister Matteo Piantedosi told Italian lawmakers on September 30.
- A group calling itself iamnotavillain publicly demanded about 6,000 Monero, roughly $3 million, according to Crowdfund Insider.
- Reports cited by Crowdfund Insider say no money was stolen, and that what left the bank was identity documents and personal information.
- Of the 680 affected customers, 55 are in France, Revolut's Western Europe chief Béatrice Cossa-Dumurgier told broadcaster BFM TV.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure Banks must hand customer data to authorities on request, so whoever controls a genuine government mailbox can reach customer files without breaching a bank's systems at all.
- contradiction Revolut earlier said it had received no ransom demand, yet Crowdfund Insider reports a public one, so it is unclear whether the group ever approached the bank directly.
- precedent By promising to pay for new identity documents in a leak where no money was stolen, Revolut has set the remedy its customers can expect if identity data leaks from it again.
Banks are required to send customer data to authorities when asked as part of criminal investigations [11]. The attacker used that duty. Cossa-Dumurgier said Revolut's own systems had not been compromised [7]. That can be true while the data still left the bank. It went out in reply to what Revolut treated as legitimate official requests [2], sent from a police address that hackers had taken control of [12][8].
Piantedosi puts the failure on Revolut. He told lawmakers the bank could have and should have verified the request with minimal due diligence [13]. Cossa-Dumurgier said government agencies are sometimes the "weak link" in the system [7]. Both statements fit the record: the police lost control of a mailbox, and Revolut sent 680 customers' data to an address with no history of use [2][12].
Spread across those 680 customers, the roughly $3 million the group demanded [3] comes to about $4,400 a record [17], the price the group put on each one, or rather the price it asked for in public. Revolut says it will not pay ransoms [4]. "If they ever have to change their ID documents, we're taking care of the associated costs," Cossa-Dumurgier said [6]. She did not say whether any customer had yet changed a document or what the pledge could cost [9].
Revolut said it passed 70 million customers in January [16], so the 680 are roughly one customer in every 103,000 [18]. If none of them replaces a passport, the pledge costs nothing. If the records are published or sold, replacement stops being a choice for some of them and the pledge becomes a real expense. If Piantedosi's account stands, the lasting cost is a change to how Revolut vets official requests, starting with whether an address has ever been used before.
I think the third outcome is where the money goes. The pledge is limited to 680 people, while the request channel stays open to anyone who takes over a government mailbox. The view is wrong if the records turn up in fraud against those customers; then the replacements become the larger bill. Revolut is not arguing the point in public, and a spokesperson declined to comment on the minister's remarks [14].
The evidence covers one bank and one Italian police mailbox. Revolut is the only firm in it to have offered to pay for new identity documents [1].
What to watch
- Whether Revolut discloses how many of the 680 customers have replaced passports or similar documents, and what it has paid for them.
- Whether the group that demanded 6,000 Monero publishes or sells the 680 customers' records.
- Whether Revolut answers Piantedosi's due-diligence charge or changes how it verifies official data requests.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+12
- Incentives70
- Confidence60
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Béatrice Cossa-Dumurgier, Revolut's chief executive for Western Europe, told French broadcaster BFM TV that the company will cover the cost of replacing identity documents for affected customers.
ReportedSupportedSource: Crowdfund Insider, citing BFM TV2 sources— create a free account to open themView cited source - [2]
In September, someone controlling an email address on an Italian government domain sent Revolut requests for customer information; Revolut treated them as legitimate official requests and sent data on 680 customers to an illicit user.
ReportedSupportedSource: Crowdfund Insider, citing reports2 sources— create a free account to open themView cited source - [3]
A group calling itself "iamnotavillain" publicly demanded about 6,000 Monero, approximately $3 million.
ReportedSupportedSource: Crowdfund Insider2 sources— create a free account to open themView cited source - [4]
Cossa-Dumurgier told BFM TV the company would not pay ransoms to hackers, when asked if it had paid one.
- [5]
Revolut previously said it had not received a ransom demand.
- [6]
"If they ever have to change their ID documents, we're taking care of the associated costs"
ReportedSupportedSource: Béatrice Cossa-Dumurgier, quoted by CNA2 sources— create a free account to open themView cited source - [7]
Cossa-Dumurgier said government agencies are sometimes the "weak link" in the system and that Revolut's own systems had not been compromised.
- [8]
Revolut said it had sent the customers' personal data to hackers who had taken control of an Italian government agency email address.
- [9]
Cossa-Dumurgier did not specify whether any customer had yet changed ID documents or how much the commitment could cost the company.
- [10]
Cossa-Dumurgier said Revolut had provided assistance for the 680 affected clients, 55 of whom are in France.
- [11]
Financial institutions are required to send customer data to authorities when asked to do so as part of investigations into potential crimes.
- [12]
Italian Interior Minister Matteo Piantedosi told lawmakers on September 30 that the email address to which Revolut sent customer data came from the Reggio Calabria police's email system but had never been used before.
- [13]
Piantedosi said Revolut could have and should have verified the request by doing minimal due diligence.
- [14]
A Revolut spokesperson declined to comment on the interior minister's remarks.
- [15]
Reports indicate that, beyond identity documents and information, no funds have been stolen.
- [16]
Revolut had 68.3 million retail customers and 767,000 business customers at the end of 2025, and said it passed 70 million customers in January 2026.
- [17]
The roughly $3 million ransom demand works out to about $4,400 per affected customer.
- [18]
The 680 affected customers are roughly one in every 103,000 of Revolut's more than 70 million customers.
Sources
2 independent publishers whose own reporting we read for this story.
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Digital BankingFollow
- Data BreachesFollow
- Fraudulent law-enforcement data requestsFollow
- Ransomware and ExtortionFollow