Free report · The Revolut breach

The Revolut breach exposed a bigger problem.

Criminals used a legitimate government email domain to obtain sensitive customer records. Understand how it happened, what remains unverified, and what your team should check before answering its next request.

What's inside
01

The breach and its aftermath: customer records, competing hacker claims, and reported ransom demands. A sourced account of what happened and what remains unresolved.

02

How the requests appeared legitimate: why a genuine government email can carry a fraudulent request, and how criminals buy access to police accounts.

03

What to check at your company: what Kodex recorded before the disclosure, how different verification checks work, and four questions to guide a review of your own requests.

✓ Delivered by email
✓ 25 pages, four parts, 17 sources
✓ Unsubscribe anytime
The Revolut Breach, Explained. Report cover.
01 · What happened

About 680 customers affected, according to reporting.

Revolut says it disclosed customer records after receiving fraudulent requests from a legitimate government email domain. The exposed information included identity documents, verification selfies, and financial records. Reporting has since linked the requests to an Italian prefecture and described a campaign lasting months. Rival claimants have disputed responsibility, while reported ransom demands have added to the uncertainty. The report follows those developments and distinguishes confirmed statements from unresolved claims.

02 · How the requests appeared legitimate

A genuine domain does not establish an authorized requester.

An attacker controlling a real agency mailbox may send messages that pass email authentication. Italy’s certified email system can also provide a valid delivery record without establishing the sender’s authority to request customer data. The market for that access predates the Revolut disclosure. Listings collected by Kodex advertised Italian police email accounts for $200 and an EU police account for $1,000, with a matching forged ID offered for another $300.

03 · What your team can learn

Use the evidence to review your own requests.

Kodex flagged Italian police and Interior Ministry certified-email domains in January. Several accounts on the domain later identified in reporting attempted to register with Kodex during 2026. None passed verification. The report explains what those findings establish, how they inform verification, and what to look for in your own records: who requested the data, how they were checked, what was disclosed, and whether related requests reached other teams.

Get the free report