Attackers allegedly stole Revolut customer data by sending fraudulent “government” legal requests for roughly five months. The requests appeared legitimate because they came from a compromised government employee email account, leading Revolut to comply and disclose sensitive personal and financial data. The attacker later demanded $3M and threatened to sell the data publicly.
How the Attack Worked
According to reporting, attackers compromised a government employee's email account, tied to the pec.interno.it domain associated with the Italian Ministry of the Interior, using an infostealer infection. From that account, they sent fraudulent legal requests to Revolut Bank UAB posing as an official government agency. Because Revolut is required to respond to legitimate law enforcement requests, the requests were treated as valid and the company complied, disclosing sensitive personal and financial data on roughly 680 customers, described as cryptocurrency whales. This campaign reportedly continued for about five months before it became public.
Why It Succeeded
The core reason this worked is that the requests came from a real, compromised government email account rather than a spoofed or lookalike domain. That authenticity removed the usual visual red flags defenders are trained to spot. Compliance and legal teams, operating under a legal obligation to respond to law enforcement, prioritized speed and procedural compliance over independent verification of the requesting party. Hudson Rock's assessment that the attacker likely used purchased infostealer logs rather than directly targeting the government employee also shows how credential theft far outside an organization's own environment can still be weaponized against it.
What to Watch For
- Urgent legal or government data requests arriving by email with pressure to respond quickly
- Requests relying on the sender's stated authority rather than routing through a verified, standard intake process
- High-value or sensitive data requests approved without independent confirmation of the requesting agency or contact
- Later contact from a threat actor publicly demanding payment or threatening to sell data, which signals extortion following a breach
Building Resistance
Organizations that regularly field legal and government data requests should treat that workflow as high-risk by default. Key steps include:
- Requiring independent verification of any legal or law enforcement request through a known, separate channel before releasing customer data
- Training compliance, legal, fraud, and customer support staff to recognize that even authentic-looking government email addresses can be compromised
- Establishing a clear escalation path to incident response when extortion demands or threats to sell stolen data surface, even if no direct contact has been made with the organization
- Reviewing data request procedures periodically to ensure urgency alone never bypasses verification steps
This case shows that authority-based trust in email, even from a legitimate domain, is not a substitute for verifying the actual requester through a separate, trusted channel.
Key findings
- Attackers allegedly obtained Revolut customer information by posing as a government agency and sending fake legal requests over an extended period.
- The fraudulent requests were sent from a compromised government employee email account (domain: pec.interno.it), increasing credibility and reducing suspicion.
- Roughly 680 customers’ personal and financial information was reportedly exposed, with victims described as “cryptocurrency whales.”
- A threat actor named “IAmNotAVillain” publicly demanded $3 million and threatened to sell the data, though Revolut said it had not received a direct ransom demand.
- Hudson Rock assessed the attackers likely used purchased/previously-collected infostealer logs rather than directly infecting those government employees.
Who’s being targeted
- Commonly targeted roles: Compliance, Legal, Fraud/AML, Customer Support (data requests), Security/Incident Response, Executives handling regulatory/law-enforcement engagement.
- Affected industries: Financial services / Fintech, Banking, Government / Law enforcement.
- Attack channels: email.
- Impersonated: An official government agency / law enforcement (using a compromised government email account).
Red flags to watch for
- Unexpected urgency and pressure to comply quickly
- Request comes via email and relies on the sender’s authority rather than standard verified intake channels
- Lack of independent verification of the requesting agency/contact despite highly sensitive data being requested
Frequently asked questions
How did attackers get Revolut to hand over customer data?
They compromised a government employee's email account and used it to send fraudulent legal requests to Revolut, which complied because it is required to respond to law enforcement requests.
How many customers were affected?
Roughly 680 customers, described as cryptocurrency whales, reportedly had personal and financial information exposed.
Did the attacker demand a ransom?
A threat actor calling themselves IAmNotAVillain publicly demanded $3 million and threatened to sell the data, though Revolut said it had not received a direct ransom demand.
How can organizations prevent similar attacks?
Verify legal or government data requests through independent, known channels before releasing customer data, since even legitimate-looking government email accounts can be compromised.
Read the video transcript
Revolut handed over crypto‑whale data for months… to fake government orders sent from a real gov email. Attackers hacked a government employee, then used their pec.interno.it inbox to send “official” legal demands. Revolut, required to answer law‑enforcement, sent back detailed customer records, about 680 high‑value crypto clients. The giveaway? Everything relied on email authority: urgent tone, government logo, real domain, but no check through Revolut’s own legal request portal or known contacts. Later, someone calling themselves “IAmNotAVillain” bragged and demanded $3 million. Here’s the move: if you ever get a legal or government request for customer data, stop. Don’t reply to the email. Call or use our approved legal-request channel to verify it first.