Skip to main content
AVOID.NET

Revolut Data Breach (Fake Government Request, September 2026)

avoid.net/revolut-data-breach-fake-government-request-september-202630/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·g2tMek…9wAi

Summary

On September 12, 2026, Revolut confirmed that an unauthorized third party had obtained sensitive data belonging to approximately 680 customers by submitting fraudulent information requests from a compromised email account operating inside Italy's Ministry of the Interior domain (pec.interno.it), which passed SPF, DKIM, and DMARC authentication checks. The exposed data reportedly included passport copies, identity verification selfies, IBANs, account statements, and full Bitcoin transaction histories. Revolut stated that its own systems and customer funds were not compromised, characterizing the incident as a social engineering attack against its data-request verification procedures rather than an intrusion.

Connected Entities

5 entities · 60 linked investigations
Organizations
RevolutZachXBT82Revolut Data Breach (Fake Government Request, September 2026)Monero58
Tokens
Relationships
  • Moneromentioned withBitcoin(60%)
  • Moneromentioned withZachXBT(65%)
  • ZachXBTmentioned withBitcoin(65%)
  • Revolut Data Breach (Fake Government Request, September 2026)mentioned withMonero(70%)
  • Revolut Data Breach (Fake Government Request, September 2026)mentioned withBitcoin(80%)
  • Revolut Data Breach (Fake Government Request, September 2026)mentioned withZachXBT(65%)
  • Revolut Data Breach (Fake Government Request, September 2026)mentioned withRevolut(70%)
  • Revolutmentioned withZachXBT(65%)
  • Revolutmentioned withBitcoin(70%)
Have evidence about Revolut Data Breach (Fake Government Request, September 2026)?

Timeline(7 events)

1 April 2026

Approximate start of the fraudulent data request campaign, based on reporting that the operation ran for approximately five months before discovery. The attackers allegedly used a compromised pec.interno.it email account to submit fraudulent law enforcement requests to Revolut Bank UAB.

SecurityWeek

11 September 2026

Affected Revolut customers began receiving breach notification emails disclosing that their personal and financial data may have been shared with an unauthorized third party.

TechCrunch

12 September 2026

Revolut publicly confirmed the breach to TechCrunch and other outlets, describing 'a sophisticated external impersonation scam' using a legitimate government agency email domain. ZachXBT flagged the customer notification on the same day and assessed it as a targeted high-net-worth operation.

TechCrunch / The Block

16 September 2026

The threat actor group 'iamnotavillain' posted a public extortion demand of 6,000 Monero (approximately $3 million) with a 24-hour deadline, threatening to sell the stolen customer records. The group disclosed using blockchain analysis to select the 680 targeted high-net-worth accounts.

Decrypt / Irish Times

16 September 2026

Additional reporting identified the compromised email account as associated with the pec.interno.it domain (Italy's Ministry of the Interior PEC system), specifically the Prefecture of Reggio Calabria. Hackers also claimed to have extracted 147GB of data from Italian law enforcement systems.

Irish Times / Security Affairs

17 September 2026

Revolut stated it had 'not received any direct contact or demand' from the actors behind the extortion claims. The UK Information Commissioner's Office confirmed it had received a breach report and was assessing the matter.

Irish Times / MLex

17 September 2026

Cybersecurity firm Hudson Rock reported approximately 300 compromised pec.interno.it webmail credentials in its database, suggesting the attackers obtained access via infostealer-harvested credentials rather than directly targeting government employees.

SecurityWeek / CyberInsider
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 15 of 17 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 9/18/2026, 5:06:58 PM

last updated: 9/19/2026, 12:01:36 AM

avoid.net — verified advice for a post-truth world