HomeSecurityRevolut data: 680 customers targeted after leak

Revolut data: 680 customers targeted after leak

The data of around 680 Revolut customers has reportedly been targeted after it was revealed that fraudsters used a real government email address to make fake requests. The case does not involve a breach of the financial technology company's core systems, but rather an abuse of a process that was considered trustworthy.

The new development, reported by SecurityWeek, is linked to a public ransom demand of $3 million from an individual or group using the alias “IAmNotAVillain.” Revolut, however, stated that it has not received any direct communication or demand from the specific perpetrators.

See also: Revolut: Fake government requests led to customer data leak

Revolut data after fake government request

How Revolut data was exposed

Revolut had confirmed on September 12 that an unauthorized third party had been making requests from an email address that belonged to a legitimate government agency. The messages passed address authenticity checks and were treated as official correspondence.

According to TechCrunch, the company blocked the address once it discovered the fraud, notified the relevant authority, law enforcement, and regulators, and stressed that Revolut's systems and customer funds were not affected.

The notifications to affected customers include names, dates of birth, addresses, emails, phone numbers and copies of passports or driving licenses. They may also include verification selfies, bank statement copies and transaction history, but not all categories have been confirmed for everyone.

The company’s initial statement spoke of a limited number of customers and direct contact with them. The subsequent picture is more concerning, as reports speak of repeated requests over months and customers with intense cryptocurrency activity. This raises the risk of targeted fraud, even if no codes or funds were accessed.

The attack exploited trust in the process, not a software flaw. When a message comes from a real government address, technical checks can show that the message is authentic, but they don't answer the question of whether the sender had the right to request the specific information.

Revolut customer data exposed

SecurityWeek reports that around 680 customers, several of whom reportedly had significant cryptocurrency activity, were affected. The number is a journalistic estimate and not an official count from Revolut, which only spoke of a “limited number” and did not name the government agency.

For these people, the leak is not limited to an email address. Identification documents, contact information, and financial history can be used for convincing phone scams, fake account recovery requests, or blackmail. The absence of money theft today does not eliminate the risk of later abuse.

See also: Trezor: Phishing attack targeted 347,000 emails

The ransom demand and unconfirmed claims

The person who goes by the name “IAmNotAVillain” claims that the campaign lasted for about five to six months and is threatening to sell the files. SecurityWeek also notes an alleged theft of more than 147 GB from an Italian law enforcement agency. These claims have not been confirmed by Revolut or Italian authorities.

The Irish Times describes the perpetrators' claims about an Italian certified email system, but does not present independent confirmation. The distinction is crucial: it is the disclosure of information following a fraudulent request that is confirmed, not any subsequent threat or claim.

Revolut data protection from social engineering

What does the case show about security?

The case shows that SPF, DKIM, and DMARC checks are not enough to prove that a request is essentially legitimate. A real government address can be used by a compromised account or an unauthorized user, and the response process must include independent verification through a second channel. Thus, the Revolut data became available without the need for a database breach.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The SecNews technical team recommends that businesses require double-checking for requests involving personal or financial information, log any exceptions, and train employees on social engineering. Customers who received a notification should be on the lookout for targeted fraud attempts and avoid new requests asking for passwords or documents.

See also: Japanese Digital Service: Data leak after VPN attack

Revolut data remains at the center of an investigation that combines breach of trust, false claims, and public threats. Until there are formal findings, reports of the 680 customers and the ransom should be presented with clear attribution and without being turned into documented facts.

Revolut data and customer leak
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS