Revolut Tricked by Fake Govt Requests for Months

Security Week Feed · High sophistication
Last updated September 18, 2026

Attackers allegedly stole Revolut customer data by sending fraudulent “government” legal requests for roughly five months. The requests appeared legitimate because they came from a compromised government employee email account, leading Revolut to comply and disclose sensitive personal and financial data. The attacker later demanded $3M and threatened to sell the data publicly.

How the Attack Worked

According to reporting, attackers compromised a government employee's email account, tied to the pec.interno.it domain associated with the Italian Ministry of the Interior, using an infostealer infection. From that account, they sent fraudulent legal requests to Revolut Bank UAB posing as an official government agency. Because Revolut is required to respond to legitimate law enforcement requests, the requests were treated as valid and the company complied, disclosing sensitive personal and financial data on roughly 680 customers, described as cryptocurrency whales. This campaign reportedly continued for about five months before it became public.

Why It Succeeded

The core reason this worked is that the requests came from a real, compromised government email account rather than a spoofed or lookalike domain. That authenticity removed the usual visual red flags defenders are trained to spot. Compliance and legal teams, operating under a legal obligation to respond to law enforcement, prioritized speed and procedural compliance over independent verification of the requesting party. Hudson Rock's assessment that the attacker likely used purchased infostealer logs rather than directly targeting the government employee also shows how credential theft far outside an organization's own environment can still be weaponized against it.

What to Watch For

  • Urgent legal or government data requests arriving by email with pressure to respond quickly
  • Requests relying on the sender's stated authority rather than routing through a verified, standard intake process
  • High-value or sensitive data requests approved without independent confirmation of the requesting agency or contact
  • Later contact from a threat actor publicly demanding payment or threatening to sell data, which signals extortion following a breach

Building Resistance

Organizations that regularly field legal and government data requests should treat that workflow as high-risk by default. Key steps include:

  • Requiring independent verification of any legal or law enforcement request through a known, separate channel before releasing customer data
  • Training compliance, legal, fraud, and customer support staff to recognize that even authentic-looking government email addresses can be compromised
  • Establishing a clear escalation path to incident response when extortion demands or threats to sell stolen data surface, even if no direct contact has been made with the organization
  • Reviewing data request procedures periodically to ensure urgency alone never bypasses verification steps

This case shows that authority-based trust in email, even from a legitimate domain, is not a substitute for verifying the actual requester through a separate, trusted channel.

Key findings

  • Attackers allegedly obtained Revolut customer information by posing as a government agency and sending fake legal requests over an extended period.
  • The fraudulent requests were sent from a compromised government employee email account (domain: pec.interno.it), increasing credibility and reducing suspicion.
  • Roughly 680 customers’ personal and financial information was reportedly exposed, with victims described as “cryptocurrency whales.”
  • A threat actor named “IAmNotAVillain” publicly demanded $3 million and threatened to sell the data, though Revolut said it had not received a direct ransom demand.
  • Hudson Rock assessed the attackers likely used purchased/previously-collected infostealer logs rather than directly infecting those government employees.

Who’s being targeted

  • Commonly targeted roles: Compliance, Legal, Fraud/AML, Customer Support (data requests), Security/Incident Response, Executives handling regulatory/law-enforcement engagement.
  • Affected industries: Financial services / Fintech, Banking, Government / Law enforcement.
  • Attack channels: email.
  • Impersonated: An official government agency / law enforcement (using a compromised government email account).

Red flags to watch for

  • Unexpected urgency and pressure to comply quickly
  • Request comes via email and relies on the sender’s authority rather than standard verified intake channels
  • Lack of independent verification of the requesting agency/contact despite highly sensitive data being requested
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers get Revolut to hand over customer data?

They compromised a government employee's email account and used it to send fraudulent legal requests to Revolut, which complied because it is required to respond to law enforcement requests.

How many customers were affected?

Roughly 680 customers, described as cryptocurrency whales, reportedly had personal and financial information exposed.

Did the attacker demand a ransom?

A threat actor calling themselves IAmNotAVillain publicly demanded $3 million and threatened to sell the data, though Revolut said it had not received a direct ransom demand.

How can organizations prevent similar attacks?

Verify legal or government data requests through independent, known channels before releasing customer data, since even legitimate-looking government email accounts can be compromised.

Read the video transcript

Revolut handed over crypto‑whale data for months… to fake government orders sent from a real gov email. Attackers hacked a government employee, then used their pec.interno.it inbox to send “official” legal demands. Revolut, required to answer law‑enforcement, sent back detailed customer records, about 680 high‑value crypto clients. The giveaway? Everything relied on email authority: urgent tone, government logo, real domain, but no check through Revolut’s own legal request portal or known contacts. Later, someone calling themselves “IAmNotAVillain” bragged and demanded $3 million. Here’s the move: if you ever get a legal or government request for customer data, stop. Don’t reply to the email. Call or use our approved legal-request channel to verify it first.

Similar attacks

Revolut Tricked by Stolen Govt Email

Revolut Tricked by Stolen Govt Email

Attackers used a compromised government email account to pose as authorities and request customer records from Revolut. Employees believed the requests were legitimate and voluntarily sent sensitive customer information, exposing data for nearly 700 people. The incident highlights how “trusted”…

September 18, 2026
Revolut Tricked by Fake “Emergency” Data Requests

Revolut Tricked by Fake “Emergency” Data Requests

Revolut confirmed it disclosed sensitive customer information after fraudsters sent “emergency” information requests from a legitimate government email domain. The attackers appear to have targeted high-net-worth customers, including people involved in crypto, and attempted to extort Revolut to…

September 14, 2026
Revolut Users Hit With SMS Phish After Breach

Revolut Users Hit With SMS Phish After Breach

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness”…

September 17, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Revolut Tricked by Fake Government Email Requests

Revolut Tricked by Fake Government Email Requests

Revolut confirmed a breach after an attacker impersonated a government agency and sent fraudulent data requests from what appeared to be a legitimate government email domain. Employees processed the requests as normal legal-compliance work, leading to exposure of sensitive customer identity and…

September 14, 2026
FBI Warns of OAuth Consent Phishing Tricks

FBI Warns of OAuth Consent Phishing Tricks

A SecurityWeek roundup highlights multiple real-world scams and campaigns where attackers trick people rather than “hack” systems directly. Notable items include OAuth “consent phishing” (getting users to approve a malicious app’s access), and phishing-evasion using invisible Unicode characters…

September 11, 2026