British fintech Revolut notified around 680 customers that their personal data had been handed over to an unauthorized third party. The scammers posed as representatives of a government agency and sent requests from that agency's legitimate email domain. The company confirmed the incident on September 12, 2026.
Revolut initially described the number of affected customers as "very limited". The Financial Times later reported that 680 customers had been contacted directly.
How the attack on Revolut unfolded
The first to publicly write about the issue was on-chain investigator ZachXBT — he received Revolut's notification on the evening of Friday, September 12, and published it. In his assessment, the attack targeted high-net-worth customers.
In a statement, Revolut called the incident a sophisticated external impersonation scam. The company confirmed it had blocked the email address after discovering the deception and had notified the government agency itself, law enforcement, and regulators.
Revolut's systems and customer funds are unaffected, — a company spokesperson said.
Revolut did not disclose which specific government agency was used in the attack.
The Italian trail and the names of the hacker groups
The technical side of the attack surfaced in the most detail through Italian media. Screenshots show that the files traveled through the official certified mailbox (PEC) of Revolut's Italian branch — [email protected], registered on the InfoCert network as the Milan branch's address. The ordinary email for the same type of requests is [email protected].
According to La Stampa, the second certified address from which the fake requests were sent may have belonged to the Guardia di Finanza (Italy's financial police) or to UIF, the anti-money-laundering unit of the Bank of Italy. Revolut does not confirm this, and Italian authorities have not commented.
At least two groups have claimed responsibility for the attack. One is Revolut Smilik (Smilik is a transliteration of the Russian word for "smiley face"), which contacted City AM. The second is IAmNotAVillain, which has its own website with an ironic name. Italian media links the PEC-address story specifically to IAmNotAVillain.
A 10,000 BTC ransom and the scale of the leak
According to Telegram channels where the hackers post sample files, the ransom figure being discussed is around 10,000 bitcoin. Revolut has said nothing about the financial side, and no payments have been recorded.
The company continues to describe the number of victims as "limited", with around a dozen names publicly known. Among the confirmed victims are tennis player Alexander Shevchenko and Felix Römer, CEO of crypto casino Gamdom.
The hackers claim that most of the victims are in Switzerland and France. Part of the list they provide (Turkey, Monaco, the Bahamas) fits poorly with a typical Revolut client, so the list is treated as unverified.
What Revolut customer data was leaked
According to the notification sent to affected customers, the hackers obtained dates of birth, postal and email addresses, phone numbers, and copies of identity documents — passports and driver's licenses. Verification selfies, account statements, and transaction history may also have been shared.
Separately, Investing.com citing the FT reported that the leak also included bank account numbers, home addresses, ID cards, and Bitcoin transaction records.
Beyond the standard identity-theft risk, customers face a physical risk as well. In France, other leaks have already been followed by cases where such data led to visits to victims' homes — the perpetrators knew both the address and the balance.
The ICO and FCA investigation
On September 14, 2026, the UK's Information Commissioner's Office (ICO) announced the launch of an investigation into the incident. Revolut had self-reported to the ICO several days earlier. According to City AM, the FCA (Financial Conduct Authority, the UK's financial regulator) has also been informed of the incident.
