Revolut Breach: Day 5 Update

Day five of the Revolut breach: a claimed six-month operation through Italian law enforcement systems, a disputed 10,000 bitcoin demand, and what Revolut has confirmed.

Kodex News
Kodex

Published on

September 15, 2026

Contents

Wants to share it ?

The Revolut story is moving fast. Here is where things stand today.

  • A six-month operation, according to a new claimant. IAmNotAVillain says compromised Italian law enforcement systems were used to request Revolut customer records over several months.
  • Responsibility is disputed. The new claimant says a former associate received a small sample of the data and then took credit for the breach.
  • A reported demand for 10,000 bitcoin. People claiming responsibility have threatened further releases of customer information. Revolut has not confirmed the ransom amount.
  • 147GB of police data allegedly stolen. That figure refers to material reportedly taken from Italian law enforcement systems, separate from the Revolut records.
  • Nearly 700 customers notified. Revolut has confirmed the disclosure. The broader claims about the operation's duration, police access and other companies remain unverified.

The person now claiming responsibility for the Revolut breach says the operation lasted six months, involved access to several Italian law enforcement departments and yielded 147GB of police data alongside Revolut customer records. That account would substantially expand an incident first disclosed as fraudulent requests sent from a government email address. The claims remain unverified. Reporting on the six-month claim

It also challenges the story that emerged over the weekend, when customer documents began circulating and a reported demand for 10,000 bitcoin became public. The new claimant, using the name IAmNotAVillain, says a former associate was given a small sample of the data and then claimed responsibility for the breach. Reported ransom demand, account of the competing claim

That leaves two questions at the centre of the investigation: who obtained the records, and how much activity preceded the disclosure?

Timeline

  • Friday, September 11. Revolut emails affected customers. The notice says the request "carried valid domain authentication credentials." Confirmed.
  • Saturday, September 12. Revolut confirms to TechCrunch "a sophisticated external impersonation scam" through a government agency domain, and says systems and customer funds are unaffected. Confirmed.
  • Sunday, September 13. Customer documents appear on Telegram and X. A group posting as Revolut Smilik threatens "more and more data everyday." Claim.
  • Monday, September 14. The demand is reported at 10,000 bitcoin. The ICO says it is assessing a report. Affected customers speak on the record. The demand is a claim; the ICO report is confirmed.
  • Tuesday, September 15. The count is put at about 680. The FCA confirms it is investigating. IAmNotAVillain claims six months inside Italian law enforcement systems and 147GB of police data, and says an associate took credit. Il Sole 24 Ore reports an interno.it address. The count and the FCA are confirmed; the rest is claimed or disputed.

Over the weekend, a group calling itself Revolut Smilik threatened to publish more customer information unless it was paid. City AM reported that the group confirmed it was seeking payment in exchanges on Telegram. The reported demand was 10,000 bitcoin. Revolut has not confirmed that amount. City AM, Disruption Banking

Posts on the Revolut Smilik Telegram channel: 'Revolut demise on the way,' 'We're gonna start releasing more and more data everyday until revolut pays for leaking their customers,' and 'Example 1 Revolut exposes a well known crypto casino owner. Coming today.' Sender names are redacted.
Posts on the Revolut Smilik Telegram channel, September 13 to 14, 2026, as captured by Marcel van Oost. Redactions are his.

A website associated with IAmNotAVillain subsequently offered a different account. According to statements reproduced by fintech commentator Marcel van Oost, its operator says the person taking credit had worked with them and received only a small portion of the records. The operator claims that Revolut and other companies supplied the data directly to them. Account of the website's claims

The IAmNotAVillain website. A notice section says Revolut got a report about a user database and ignored it, and claims to hold KYC documents, addresses, phone numbers, emails, bank accounts and transactions. A warning section says an impersonator who used to work with them took a small sample and is now claiming the breach as his.
The IAmNotAVillain site, September 14, 2026, as captured by International Cyber Digest. The domain no longer resolves.

This does not establish which account is true. But it means the people publicising the data and demanding money cannot simply be assumed to be the people who originally obtained it. Nor does possession of a sample establish possession of the full dataset.

Not one incident. Six months of fraudulent requests.

In an interview reported by International Cyber Digest, IAmNotAVillain said the operation targeting Revolut ran for six months. They claimed to have compromised multiple Italian law enforcement departments and used those systems to send requests for customer information. Interview account reproduced here

If substantiated, that would mean investigators need to reconstruct months of activity: which accounts were used, how many requests were sent, what each requested and which companies answered.

The reference to other companies raises the possibility that Revolut was one of several recipients. No other company's involvement is established by that statement, and the material reviewed does not establish the use of government credentials from countries beyond Italy.

Hackers claim to have 147GB of user data

The claimant says they also obtained 147GB of material from the Italian law enforcement systems, including internal documents, calendars and personal communications. That is the claimed police dataset, separate from the Revolut customer records. Its size and contents have not been independently verified. Reporting on the claimed police data

The allegation would make the agencies victims of data theft themselves, while their systems were also being used to obtain information from companies.

Il Sole 24 Ore separately reported that documents circulated by the attacker showed an address ending in interno.it, the domain of Italy's Ministry of the Interior. Neither Revolut nor the ministry has publicly confirmed that identification.

What Revolut has confirmed

Revolut says an unauthorised party submitted fraudulent requests through an email account on a legitimate government agency domain. The messages passed domain authentication checks, and the company disclosed customer information believing the requests were genuine.

The company says it blocked the address, alerted the agency and relevant authorities, and notified affected customers. Its systems and customer funds were unaffected. Revolut's statement reported by The Block

Revolut told Il Sole 24 Ore it notified just under 700 people; the Financial Times reported 680.

The customer notice listed information that may have been disclosed, including identity documents, verification selfies, addresses, phone numbers, account statements and transaction histories, including bitcoin transactions. Those records can connect a person's identity and home address to detailed financial activity. The Block

The question for every company receiving these requests

Revolut's confirmed account and the broader allegations meet at the same point: the requests arrived through a government domain.

Email authentication cannot establish whether the person using an account is an authorised investigator or whether a particular request is legitimate. If an attacker controls a genuine agency account, messages sent through it can still pass authentication.

The six-month claim makes the history of those requests especially important. If the same compromised accounts contacted multiple companies over time, each recipient may hold only part of the evidence needed to understand the operation.

For companies reviewing their own records, the immediate questions are practical: who requested the information, how was their authority established, and what was released?

The next developments to watch are confirmation of the agency involved, the period during which its accounts were used and whether other companies received requests. Those answers will determine how far this incident extends beyond the customers Revolut has already notified.

Teams handling government requests can check a requester's verification status through Kodex Verify.

Get Your Free Drone Autonomy Guide Today!

Use this guide to identify your specific support software needs, understand the types of solutions to look for, and get leadership buy-in.
Get the Guide