Breaking News

Revolut Breach Exposes the Authentication Gap in Government Data Requests

Written by Maria-Diandra Opre | Sep 24, 2026, 12:00:01 PM

Why steal customer records when you can convince a bank to hand them over? Revolut disclosed sensitive data to miscreants after receiving fraudulent requests from what appeared to be a compromised government email account.

Whoever controlled the account turned its official status into access to customers’ private information. Revolut released the data believing the requests were genuine, while its own banking infrastructure and customer funds remained unaffected (Reuters, 2026). The group claiming responsibility later said the operation had lasted roughly six months, although that timeline has yet to be independently verified.

Italian authorities are now investigating whether a certified PEC email account associated with the prefecture of Reggio Calabria was compromised. The account has been linked to the Prefecture of Reggio Calabria. Italian prosecutors have opened an investigation, although investigators have yet to establish whether a computer belonging to the prefecture or the Interior Ministry was actually compromised. The messages reportedly continued over several months before Revolut contacted the institution directly and discovered that the requests were fraudulent (ANSA, 2026).

Around 680 customers were caught up in the scheme. The attackers allegedly concentrated on people with substantial cryptocurrency holdings, using blockchain analysis to identify potential targets. Most affected customers were in France and Switzerland, although customers in another 31 European countries were also involved (Financial Times, 2026).

The records were far more valuable than a standard contact-data leak. Notifications said the disclosure could include:

  • Names, dates of birth, home addresses and phone numbers
  • Passports, driving licenses and verification selfies
  • Account statements and transaction histories

A criminal with a passport image, home address, and genuine transaction history can mount an impersonation attempt with far more credibility than someone using a leaked email address. Crypto holdings introduce another concern, since detailed financial records can help identify customers worth targeting for SIM swapping, extortion, or highly personalized phishing.

The case has already taken on a ransom angle, as Reuters reported that people claiming responsibility threatened to sell information belonging to hundreds of customers unless Revolut paid $3 million, citing the Financial Times. Revolut said it had received no direct ransom demand from the alleged attackers (Reuters, 2026).

A request can come from the correct domain and still deserve independent verification. Sensitive requests need checks tied to the requester, case authority, and scope of disclosure, especially when unusually broad records are sought or the same channel repeatedly asks for high-value customer data. The Revolut requests appear to have landed in the gap between those two forms of trust: the email looked official, while the authority behind it apparently was not. For banks handling government requests at scale, that gap is now a much harder one to treat as administrative routine.