Digital Bank Revolut Denies Direct Contact From Group Claiming Data Breach Ransom

Revolut has stated that it has not received any direct ransom request from people claiming responsibility for a recent customer-data incident. The digital bank said it has had no contact from the group that later posted a public ultimatum online.

The company first disclosed the problem on 12 September 2026.

An unauthorized party used an email account on a genuine government-agency domain to send fraudulent information requests.

Revolut treated those messages as official legal demands and supplied records over a period of months.

Once the deception was identified, the firm blocked the address, notified the relevant government body, law enforcement, data-protection authorities and financial regulators, and contacted the customers involved.

Revolut has stressed that its own systems, databases and customer accounts were not penetrated.

Customer funds were not taken.

A source familiar with the matter has said the episode involved roughly 680 customers rather than a mass compromise of the platform’s tens of millions of users.

Many of those accounts appear to have been selected because of suspected cryptocurrency activity.

The material that left the company included names, dates of birth, postal and email addresses, phone numbers, copies of passports and driving licences, verification photographs, account statements, IBANs and transaction histories, including Bitcoin activity.

Revolut has described the episode as a sophisticated impersonation scam rather than a conventional hack of its infrastructure.

Days after the disclosure, a group using the name iamnotavillain published an online demand.

It asked for payment equivalent to about $3 million in Monero within 24 hours and threatened to sell the records to other criminal groups if the money was not paid.

The Financial Times reported that the group said it had used a compromised Italian government email system to pose as law enforcement and that it had chosen targets through blockchain analysis.

The same group told the newspaper it had not negotiated privately with Revolut and was using the website to make its first public demand.

Revolut’s response was unambiguous.

A spokesperson told Reuters that the company had received no direct contact or demand from the individuals or group making the claims.

Similar statements were given to other outlets.

The distinction matters: a public countdown on a third-party site is not the same as a ransom note delivered to the bank itself.

The case has drawn attention because it exploited a routine compliance process rather than a software vulnerability.

Banks and payment firms are required to respond to legitimate government and law-enforcement requests.

When those requests arrive from an authenticated official domain, technical checks can still pass.

The incident therefore raises questions about how financial firms verify the substance of legal demands even when the sending infrastructure looks genuine.

Revolut says it has already informed the small number of affected customers and offered support.

Italian authorities have begun examining the reported compromise of government email accounts.

As of mid-September 2026 there was no independent confirmation that the records had been sold after the public deadline passed.

The episode leaves Revolut managing reputational risk rather than a collapse of its core systems. For customers whose identity documents and transaction histories were handed over, the practical danger is targeted fraud or further extortion attempts that sit outside any payment the company itself might or might not make.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend