“Their blood will be on Revolut's hands, not mine:” Attackers threaten to sell customer data unless they’re paid $3M
Hackers threaten to sell Revolut customer data in less than 24 hours.

Image via Shutterstock
- Hackers claim they stole Revolut customer data and threaten to sell it unless paid $3 million.
- Researchers say attackers used a stolen Italian government email account to send fake data requests.
- Revolut allegedly sent hundreds of files on high-value crypto users before verifying the requests.
- The Italian office behind the spoofed requests had no authority to seek foreign banking data.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Even more sensitive customer data has been released as attackers targeting Revolut pressure the fintech giant to pay $3 million.
Revolut customers around the world are facing growing uncertainty after sensitive data was allegedly exfiltrated from the financial platform serving over 75 million people.
“We have everything, including KYC documents, address, phone number, email, bank accounts, fiat and crypto transactions,” the attackers said on their website.
Just now, the hacking group behind the attack issued a final 24-hour ultimatum for Revolut to pay. Attackers also said that affected individuals can buy themselves out.
However, Revolut says that it has had no direct contact or demand from the individuals or group claiming responsibility for a data breach.
"If the ransom is not paid, then the data will be sold, and their blood will be on Revolut's hands, not mine," the hackers told the Duel investigators.
🚨 BREAKING: The Revolut hacker has announced his ransom demand.
undefined Korra (@korraflow) September 16, 2026
The hacker wants Revolut to pay $3 million USD in XMR, an anonymous cryptocurrency. If the ransom is not paid, the hacker says the data will be sold and that undefinedthe bloodundefined will be on Revolut's hands.
24 hours left. pic.twitter.com/1JRtzAVODa
Revolut hackers harvested rich clients' data
The customer data was breached this week after attackers sent a fraudulent order from a spoofed agency in Italy to obtain information.
The hackers allegedly used a stolen Italian government employee’s email account to send large numbers of cryptocurrency transaction IDs via fake European Investigation Orders (EIOs) and to request personal information associated with the accounts for months.
Revolut's team treated the request as legitimate and sent hundreds of files containing sensitive customer information. All the data belongs to high-value crypto holders or accounts that made big transactions.
‼️ BREAKING: The Revolut hacker has shared with Duel's investigation team, for the first time, a complete video showing the scale of his information treasure trove. Multiple celebrities are included in the leaks.
undefined Korra (@korraflow) September 16, 2026
The hacker plans to announce his ransom demands today.
Here's… pic.twitter.com/KFxufIZfUw
“The hackers’ goal was to obtain high-value crypto targets. This has various potential use cases in the cybercriminal world, such as online social engineering, conducting IRL robberies, reselling the information to other criminal groups, or blackmailing Revolut directly,” a Duel researcher said in the post on X.
Revolut only verified the request with the real agency after the data had been sent.
"Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators," a spokesperson told Reuters in the wake of the attack.
How was Revolut breached?
According to Duel, the attacker first gained access to an Italian government employee’s account using an infostealer. After taking control of the mailbox, the hackers allegedly added their own recovery email address and monitored incoming messages.
To hide their activity, the hackers would immediately delete emails that were not intended for the employee and monitor the inbox around the clock for responses to messages they had sent.
When a response arrived, the hackers allegedly downloaded it as an .eml file and deleted the original email before the employee could see it.
The hackers initially experimented with forging court orders when targeting other companies, but eventually identified Revolut Bank UAB, the Lithuania-based entity of Revolut, as a more suitable target.
‼️ BREAKING: Our investigations team at Duel is in contact with the Revolut hacker, and we've found out a lot more about how he did what he did.
undefined Korra (@korraflow) September 15, 2026
- The hacker got access to government employee accounts using an infostealer. After gaining access to an employee's email, they would… pic.twitter.com/z0zoCGqDpA
The hackers sent 1 request 5 months ago that Revolut fell for. The attacker then allegedly continued to send requests during this period.
The investigation team said the compromised email account also allowed the hackers to send and control messages that appeared to originate from several Italian government addresses.
Duel says that Revolut repeatedly complied with the requests without questioning their legitimacy or independently verifying them.
In one alleged incident, the hackers accidentally submitted an incorrect document. Rather than stopping the process, Revolut support allegedly told the attackers what needed to be changed.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Are the Revolut hackers amateurs?
The hackers provided Duel with videos, emails, attachments, and other material that Duel said it reviewed as part of the investigation. The stolen files contained full banking and transaction histories.
“Our understanding is that the files sent to us were just one of dozens. Each file, which comes with full banking and transaction history, would allow hackers to establish the target's daily spending patterns, location data, and people they send money to,” the Duel researcher said.
The files also contained information about a Swedish singer and former Idol finalist, an Armenian academic, an Indian cricketer, and several company founders and CEOs.
The released information is likely just a fraction of what attackers actually have in hand.
However, the team characterized the alleged operation as relatively amateur rather than a professionally organized campaign.
“Our team is under the impression that this is an amateur group that got lucky due to Revolut's lack of checks and continued incompetence over several months. This does not seem to be a professionally organized hacking group,” they said.
The Italian office wasn’t even authorized to send the orders
It’s now known that the mailbox from which the fake data requests to Revolut originated belongs to the Prefecture of Reggio Calabria.
The office is part of the administrative body. It handles matters such as public order, administrative sanctions, immigration procedures, and coordination of law enforcement at the provincial level.
It is not part of the judicial branch and has no prosecutorial or adjudicative function in criminal proceedings, nor does it have the power to issue orders for acquiring banking data abroad.
So it is a double blow to Revolut's legal team, as it not only accepted a fake EIO, but it was also coming from the entity that has no authority to issue it.