The email passed every authentication check. It came from a real government domain. And it was a scam that cost 680 people their passports, selfies, and bank histories.
On September 12, 2026, Revolut — Europe's largest fintech, with over 80 million customers — confirmed it had handed sensitive customer records to criminals. There was no break-in at Revolut: no exploited server, no leaked password. Investigators believe infostealer malware on a government employee's device handed attackers the mailbox, while Revolut's own systems were never breached — its defenses were never tested. Attackers sent data requests from an email account inside a real Italian government system, and Revolut's compliance team processed them as routine legal requests. The attackers describe the campaign as running roughly five months; Revolut has not confirmed a timeline.
If a bank with a full compliance department can be talked into handing over customer files, a small shop with one inbox and no legal team is an easier target for the same trick.
What actually happened
The attackers compromised an account in Italy's PEC system — Posta Elettronica Certificata, the certified email network Italian government bodies, courts, and law firms use for binding official correspondence. Because the messages genuinely originated from the government domain, they passed SPF, DKIM, and DMARC authentication — the technical checks designed to catch forged email. Every green tick lit up. The sender was still a criminal. Once inside the mailbox, the attackers reportedly added a recovery address, monitored ongoing correspondence, and deleted their fraudulent outgoing messages to cover their tracks.
Revolut complied, believing each request was an authentic government inquiry it was legally obliged to answer. About 680 customers were affected — a tiny fraction of 80 million, but on-chain investigator ZachXBT notes the requests appear to have targeted high-net-worth individuals and crypto holders specifically. Among those notified was former Mt. Gox CEO Mark Karpeles, who confirmed he was affected, reported the matter to police in Japan, and moved his family to a hotel as a precaution.
What was handed over reads like a complete identity-theft kit: names, dates of birth, occupations, postal and email addresses, phone numbers, passport and driving licence copies, account verification selfies, IBANs, account opening dates, full account statements and withdrawal records, and complete Bitcoin transaction histories with wallet references. What was not exposed matters too: private keys, passwords, full card numbers, and customer funds were untouched — this was a disclosure failure, not a systems breach.
An earlier demand reported September 16 sought 10,000 Bitcoin (roughly $780 million); by September 17, a group calling itself iamnotavillain had published a countdown site demanding a $3 million ransom within 24 hours, threatening to sell the records to other criminal groups, and sent the Financial Times a 60-second screen recording scrolling through purported stolen documents. Revolut told Reuters it had received no direct contact or demand from the group. The UK's Information Commissioner has opened an investigation, prosecutors in Reggio Calabria are treating it as an intrusion into a public-interest IT system, and around a dozen affected customers in Ireland may trigger a parallel inquiry there.
Why this matters to website and shop owners
You do not need 80 million customers for this to hurt you. If your shop stores customer names, addresses, ID documents, order histories, or payment details — and most ecommerce, booking, and membership sites do — you will eventually receive an email that says, in effect: "we are the police / the tax office / a lawyer / a fraud investigator, send us this customer's file."
Three things make small businesses softer targets than Revolut was:
You have no verification process. Revolut's failure was procedural, not technical — its workflow treated an authenticated email as sufficient authorization. Most small shops have no workflow at all. Whoever reads the inbox decides, alone, under time pressure, with an email that says "urgent" and "confidential."
You keep more than you need. Every ID scan, address, and order record sitting in your inbox, your uploads folder, or your admin panel is something you could one day be tricked into sending. Data you deleted on schedule cannot be disclosed by mistake.
Your staff are the compliance team. The person most likely to fall for an "official request" is whoever is newest, busiest, or most eager to cooperate with authority. Attackers count on that deference.
There is no software patch for this class of failure. The UK regulator's question — whether Revolut had "appropriate technical and organisational measures" — applies to a five-person shop too, scaled to fit. The fix is a habit, not a product.
What to do: the verify-first habit
Build one rule into your business: no customer data leaves the building on the strength of an email alone. Then make it easy to follow with four concrete steps.
Verify out of band, every time. Any request for customer data — from police, tax authorities, lawyers, payment processors, or fraud teams — gets confirmed through a second channel you look up yourself. Call the agency's published number (not the one in the email). Log into the processor's dashboard and check for a matching case. A genuine official expects this; only a scammer rushes you past it. The campaign reportedly ran for months — time in which a single call to a published number might have ended it in week one.
Give one person the authority to say "not yet." Decide in advance who handles data requests, and give them explicit permission to delay any disclosure until verification completes — even if the email says urgent, even if it names a senior person, even if it threatens consequences. Write it down. A one-paragraph policy beats good intentions at 5 p.m. on a Friday.
Keep less, for less time. Review what customer data you retain and where. Delete ID documents once verification is complete instead of archiving them "just in case." Purge old order exports from inboxes and shared drives. Set your ecommerce platform and plugins to the shortest retention your legal obligations allow. The Revolut files were valuable because they were complete dossiers; partial records are worth less to everyone, including thieves.
Limit who can see the full file. Not everyone who answers support tickets needs access to ID scans and full transaction histories. Most platforms let you restrict sensitive fields to an owner or admin role. Fewer people with access means fewer people an attacker — or a convincing email — can work through.
If you receive a suspicious request today: do not reply, do not click, do not forward it around the team. Confirm the sender through an independent channel, preserve the original message with full headers, and if customer data may already have left, treat it as an incident — contain, assess, notify.
Key numbers
- ~680 customers affected out of 80M+ (Wall Street Journal via Financial Times; Guardian, Sept 17)
- Months-long campaign: the attackers describe roughly five months of requests; Revolut has not confirmed a timeline (SecurityWeek, Sept 17; Security Boulevard)
- $3M ransom demanded on a countdown site within 24 hours (Financial Times via Guardian, Irish Times, Sept 17)
- Full dossiers exposed: passports, selfies, IBANs, statements, Bitcoin histories — but no private keys, passwords, full card numbers, or funds (Silicon Republic; Blockonomi)
- Passed SPF, DKIM, and DMARC — because the mail truly came from the government domain (CryptoSlate via Global1.News; Tech Insider)
- Regulators engaged: UK ICO investigation, Reggio Calabria prosecutors, possible Ireland DPC parallel inquiry (CryptoTimes/City AM; Gate News; Euronews)
Final takeaway
Revolut lost no servers and no money — it lost control of a process. An email that looked official was treated as authority, and 680 complete identity dossiers walked out the front door over a months-long campaign (per the attackers' account; Revolut has not confirmed the timeline). Your shop faces the same trick at smaller scale, with thinner defenses. The defense costs nothing: verify through a second channel, empower someone to pause, keep less data, and show it to fewer people. Authority arrives by email every day. Proof should be required before customer data follows it out.
Is your site ready? Run a free security scan — 40+ automated checks, instant results, no commitment.