Industry News

Fake Italian Police Emails Reportedly Tricked Revolut Into Handing Over Customer Data

Bitcoin · 17 Sept 2026
Key Takeaway Businesses should verify the identity of anyone requesting sensitive customer data through official-looking channels, especially law enforcement requests, using independent callback checks rather than trusting email authentication alone.

A group calling itself iamnotavillain claims it obtained sensitive Revolut customer data not by hacking the company's servers, but by impersonating Italian law enforcement over several months. According to reporting by the Financial Times, the attackers allegedly used Italy's certified government email system, PEC, to send requests that carried genuine domain authentication, making them appear to come from a real authority. Revolut reportedly complied, handing over records including passports, selfies, transaction histories and other verification documents.

The group says it targeted people carefully, using blockchain analysis to identify Revolut users with significant cryptocurrency activity before requesting their records by name. FT's sources put the number of affected individuals at around 680, spread across 31 countries with concentrations in Switzerland and France. The attackers are now demanding 6,000 monero, worth roughly $3 million, and have set a public countdown threatening to release the identity files to other criminals if unpaid.

This case highlights a growing risk: authenticated email from a legitimate domain does not guarantee the sender is who they claim to be. The attackers appear to have exploited the trust placed in official communication channels rather than breaking through technical defences.

Summarised by CISO AI from Bitcoin. We link back to every original so you can read it yourself.