Home Β· Wiki Β· Incidents & Campaigns
type: incident Β· created: 2026-09-17 Β· updated: 2026-09-17 Β· tags: [incident, financial-services] Β· confidence: medium Β· severity: high Β· affected_sectors: [financial-services] Β· au_impact: true

The hackers who claim responsibility for the Revolut data breach have told the Financial Times that they obtained personal details from 680 high-net-worth crypto accounts at the firm, and have described a method that is an escalation rather than a restatement of the 11–14 September disclosure. They say they compromised an Italian government email system and then exchanged messages with the bank over several months while posing as law enforcement, repeatedly requesting confidential account details for named customers β€” addresses, phone numbers and transaction histories β€” on the basis that the information was needed for ongoing investigations. Messages the hackers shared with the FT appeared to show Revolut exchanging customer account information with an arm of Italy's interior ministry through La Posta Elettronica Certificata (PEC), the certified-email network overseen by a government agency that functions as the digital equivalent of registered post. The target selection is the most notable technical claim: the group says it used blockchain analysis to identify Revolut accounts holding significant crypto assets, meaning the victims were chosen for the size of their holdings rather than harvested at random. Most of the 680 are said to be in Switzerland and France, with data on residents in a further 31 mainly European countries, including the UK, Germany and Spain. The hackers have set up a website and begun posting redacted screenshots of information allegedly obtained, and are reported to be ready to release more unless a ransom is paid; Revolut insists it has not been contacted by the perpetrators and has yet to receive a ransom demand. The company confirmed the underlying breach on 11 September, saying the request carried valid domain authentication credentials and was fulfilled "under the reasonable belief that it was an authentic government agency request".

Attribute Detail
Sector Financial Services
Date 2026-09-17
Source Finextra
Reliability Tier 2