The Revolut breach just escalated.
the attackers are now leaking customer data and demanding payment. they've started publishing passports and KYC selfies of named individuals. tennis player Alexander Shevchenko. Gamdom CEO Felix Römer. they say they'll release more every day until Revolut pays.
What's confirmed:
Attackers used a real government agency email domain, reporting points to Italian PEC infrastructure, to send fraudulent data requests to Revolut. the emails passed DKIM authentication checks. Revolut's compliance team treated them as legitimate. They handed over the data.
what was exposed: full names. dates of birth. occupation. addresses. emails. phone numbers. passport and driving licence copies. KYC selfies. IBANs. account statements. full transaction histories including Bitcoin.
What the attackers are claiming — not independently confirmed:
the group calling itself IAmNotAVillain claims:
— the operation ran for roughly six months
— they used compromised Italian law enforcement systems to send the requests
— they hold 147GB from the Italian side including
internal documents and officer chat logs
— the majority of Revolut data is from Switzerland and France plus other countries
— high-profile names include a Barcelona player and Georgia footballer Georges Mikautadze
Passports + selfies + transaction histories + IBANs = a complete identity package. enough for account takeover. identity fraud. targeted phishing that references your real transaction history to sound legitimate
if you're a Revolut customer:
— check for a notification email from Revolut. if you got one, assume your data is in the leak.
— be extremely suspicious of any contact claiming to be Revolut, law enforcement, or a bank in the coming weeks. this data will be used for follow-on attacks.
— if your passport was exposed: contact your country's passport authority about flagging it.
— freeze your credit if you're in a jurisdiction that allows it.
W! @IntCyberDigest for the discovery!
A hacker claiming responsibility for the Revolut breach now says they also compromised multiple Italian law enforcement systems and stole 147GB of data.
If true, this just got a lot bigger.
Source: @IntCyberDigest