Revolut hacker says they had six months of secret access
Personal conversations were exposed.

Image via Shutterstock
- A hacker claims they accessed Italian law enforcement systems for six months to request Revolut customer data.
- Revolut confirmed it disclosed sensitive customer information after fraudulent requests appeared to come from a legitimate agency email.
- Reports say attackers received data on nearly 700 customers, including identity documents and transaction details.
- The hacker claims the stolen data covers customers across Europe, with most records from Switzerland and France.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The hacker behind a British fintech giant’s Revolut data breach claims the operation was much bigger than first reported.
According to the threat actor, the operation against Revolut lasted six months. During that time, they broke into several Italian law enforcement departments and used their systems to request information from the financial company.
International Cyber Digest, a cybersecurity news publication, said its team had spoken with the hacker, who goes by the moniker IAmNotAVillain. The hacker has launched a website to promote the alleged stolen data.
The hacker also claims to have stolen 147GB of data from the Italian authorities. The dataset include internal documents, calendars, and personal files. The alleged haul even includes chat logs from a federal officer arguing with his wife.
The attacker told researchers that the stolen information includes data belonging to well known individuals. One of the names mentioned is a footballer for FC Barcelona, a prominent team.
They've also launched a website today. pic.twitter.com/9XQ6HpRq17
undefined International Cyber Digest (@IntCyberDigest) September 14, 2026
“We have everything, including KYC documents, address, phone number, email, bank accounts, fiat and crypto transactions,” the attacker says on their site.
IAmNotAVillain claims most of the Revolut data came from Switzerland and France. But the hacker says information on customers from many other countries was also obtained.
The affected countries include:
- Cyprus
- Portugal
- Germany
- Spain
- Bulgaria
- Czechia
- Romania
- Poland
- Malta
- Norway
- Sweden
- Italy
- Greece
- Netherlands
- Latvia
- Austria
- Belgium
- Estonia
- Croatia
- Ireland
- Slovakia
- Finland
- Lithuania
- Hungary
- Denmark
- Turkey
- Monaco
- Luxembourg
- Bahamas
- Slovenia
- United Kingdom
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Revolut falls for a scam
The reports about the breach at the fintech giant came over the weekend. Reportedly, attackers obtained Revolut customer data using an email address on a legitimate government agency domain. Exposed data included contact details, birth dates, occupations, and identity documents.
Revolut confirmed it disclosed sensitive customer information after receiving fraudulent data requests from what appeared to be a legitimate government agency email account.
"Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators," a spokesperson told Reuters on Saturday.
Reportedly, verification selfies, account statements, transaction histories, IBANs, and Bitcoin transactions may also be affected.
According to the Financial Times, Revolut handed in to attackers nearly 700 customers’ data. Hackers behind the incident are threatening to release the information to the public unless Revolut pays a ransom.