Revolut customer data exposed following sophisticated social engineering attack
AI-generated image
AI Synthesis Sources: 2

Revolut customer data exposed following sophisticated social engineering attack

A sophisticated social engineering attack targeting the financial platform Revolut resulted in the unauthorized exposure of customer data in September 2026. Experts, including network security specialist Dinos Pastos, explained that the attackers did not breach Revolut’s internal systems directly. Instead, they compromised the systems of an Italian government agency and used a legitimate official email domain to send a highly convincing request for information to the company. Revolut staff, believing the communication to be authentic, inadvertently provided specific customer data to the perpetrators.

Following the incident, a hacker group identifying itself as 'iamnotavillain' publicly demanded a ransom of 6,000 Monero, valued at approximately 3 million euros or dollars, threatening to sell the stolen data if the payment was not made within a 24-hour countdown. The compromised information reportedly includes identification documents, photos, account details, statements, and transaction histories. Revolut confirmed the incident after verifying with Italian authorities that the initial data request was fraudulent. The company has since initiated efforts to manage the aftermath of the breach. No direct breach of Revolut's core banking architecture was reported, as the data was voluntarily surrendered by staff deceived by the forged request.

Original Sources