Incident
Published 2026-09-12
Verified 2026-09-19

Revolut: Italian gov-domain impersonation — ~680 high-profile accounts; $3M ransom demand

TechCrunch (12 September 2026) and BleepingComputer (14 September) report Revolut confirmed it disclosed sensitive customer information to an unauthorised third party after fraudulent information requests were sent from a legitimate government-agency email domain. SecurityWeek (17 September 2026) adds quantified scope: attackers impersonated an Italian government agency for about five months, obtained data from roughly 680 high-profile accounts, and are demanding a $3 million ransom. A Revolut spokesperson described a sophisticated external impersonation scam; the company blocked the mailbox, alerted the agency, law enforcement and regulators, and said systems and customer funds were unaffected. Customer notifications list identity and contact details (name, date of birth, postal/email addresses, phone), copies of passports or driver’s licences, facial verification selfies, account statements (including IBAN), withdrawal records, and full transaction histories (including Bitcoin activity). Primary: TechCrunch with Revolut confirmation; NEW scope wire: SecurityWeek 17 Sep; secondary: BleepingComputer 14 Sep; not a core-system compromise.

Product
Revolut (fintech / KYC document and statement handling)
Versions
n/a (business-process / legal-request social engineering; not a product CVE)
Exploited in Australia?
unknown
Patch to
n/a for operators of other platforms: verify government legal requests out-of-band; treat unexpected KYC/doc disclosure notices as phishing risk for affected customers

Primary: TechCrunch — Revolut fake government-request disclosure (12 Sep 2026) · SecurityWeek — 680 accounts / $3M ransom / 5 months (17 Sep 2026)

breaches identity