SimpleSwap Blog

Revolut Data Leak: What Crypto Holders Should Do Now

data leaks

A week after Revolut confirmed it had released customer files in response to requests from a real government mailbox, Italian prosecutors have a domain, and the extortionists' countdown has run out without a confirmed sale. The files themselves are not coming back. Here is where things stand and what to do if you hold crypto.

What happened

On the night of September 11, a Revolut customer notice began circulating online. The on-chain investigator ZachXBT was among those who shared it, and the trade press had the story within hours. Revolut confirmed the substance the next day. An unauthorized third party, writing from an email address on a legitimate government agency's domain, had submitted requests for customer information. Staff processed them as standard legal-compliance requests and released the data.

Revolut calls it "a sophisticated external impersonation scam." According to the customer notice, the requests carried valid domain authentication, which is why they were treated as authentic. The notice also says Revolut later contacted the agency itself to validate the request and flagged the unauthorized account operating on its domain. Once the deception was spotted, the company blocked the address, alerted the agency and the relevant authorities, and said its systems and customer funds were unaffected.

Revolut has since put the number of affected customers at around 680, described as European. ZachXBT's assessment was that the targeting concentrated on high-net-worth users rather than a mass retail dump.

Where the story stands on September 18

Revolut has not named the agency. Italian investigators have. The public prosecutor's office in Reggio Calabria has opened an investigation, and the requests have been traced to a compromised certified email (PEC) account at the local prefecture, a territorial office of the Interior Ministry. Italian cyber police describe a sophisticated operation that ran for months. Italy's data protection authority has ordered checks at Italian banks and opened an exchange with its Lithuanian counterpart, where Revolut's banking entity is registered. A company spokesperson told Cointelegraph that it reported the matter to the Italian authorities upon detection and will assist as needed.

How the mailbox was taken over is coming into focus. Hudson Rock reports that, after an investigations team made contact with the attacker, the government employee's credentials came from an infostealer infection and that the compromised address is on pec.interno.it, the Interior Ministry's certified email domain. The firm says it has seen more than 300 compromised credentials tied to that domain and assesses that the attacker most likely bought existing infostealer logs rather than infecting anyone personally. By the attacker's own account, the requests went to Revolut Bank UAB, the Lithuanian entity, over roughly five months.

In the UK, the Information Commissioner's Office says it has received Revolut's report and is assessing it, and the Financial Conduct Authority says it is engaging with the firm. Neither is a finding of fault.

Then the ransom, which remains the murkiest part. Since September 13, customer dossiers have been appearing on a Telegram channel with a promise to publish more each day until Revolut pays; that account has since been suspended. A figure of 10,000 BTC circulated in the first days. On September 16, a group calling itself "iamnotavillain" posted a different demand on its own site next to a countdown clock: 6,000 XMR, about $3 million, with 24 hours to pay before the data would be sold to other criminal groups. It told the Financial Times it had not contacted the bank, and it claims to hold 147 GB of data. The same group says the 10,000 BTC demand came from a former associate holding only a sample. The countdown ran out on Thursday afternoon. As of Friday morning, no outlet has confirmed a sale or a bulk dump, and Revolut says nobody has contacted it directly and no ransom has been paid.

What can be said with confidence: the disclosure is a company fact. Everything about who holds the files and what they want is, so far, the word of people extorting a bank. One detail in that account is worth keeping anyway: by the extortionists' own telling, at least two parties hold copies.

What is in the file

The customer notice, as reported by TechCrunch and SecurityWeek, lists what may have been disclosed: full name, date of birth, occupation, home address, email address and phone number, along with copies of passports or driving licenses and the facial verification image submitted at onboarding. The financial layer included account statements with IBANs and withdrawal records. Full transaction histories were also listed, and several outlets reported that they included Bitcoin activity. The notice says no biometric facial telemetry was involved, drawing a line between the selfie itself and the biometric data derived from it. It also frames the list as categories that may have been disclosed, so not every affected person necessarily lost every category.

Among those who confirmed receiving the notice was Mark Karpelès, the former chief executive of Mt. Gox.

Read that as a list and it looks like the standard breach inventory. Read it as a single file about one person, and it looks like something else: a verified identity, a face to match it, a home address, the state of their finances and, for some, a record of where their crypto has been.

Why "someone fell for an email" is the wrong summary

Nobody broke in. The requests arrived through the channel built to receive them and were handled by the team whose job is to handle them. Banks are legally required to respond to lawful information requests from authorities; a bank that fails to do so would face a different compliance problem. The gap sits between two questions that are easy to conflate: did this message really come from that domain, and is this request really authorized? The messages passed the first test. What checks were run on the second before the data went out have not been made public.

"Domain authentication answers one question: did this message really come from that server? It says nothing about who is behind the account or whether they have the authority to ask. Domain authentication alone should not be treated as proof that a request for sensitive data is authorized. The stronger safeguard is structural, not merely a matter of staff vigilance: a request for sensitive data must be confirmed through a channel the requester did not choose, and no single person should be able to complete the release alone. That is true for a bank, and it is true for anyone else holding this kind of file."

Stefan Lauer, Head of Infrastructure, SimpleSwap

The technique has a history. In 2022, Bloomberg reported that Apple and Meta had handed user data to people sending forged emergency requests from compromised law-enforcement email accounts. Discord confirmed it had done the same. That same year, Revolut disclosed a breach affecting roughly 50,000 customers, also via social engineering, though in that case the attacker reached an internal database. In November 2024, the FBI warned companies that credentials for police and government mailboxes were being sold openly on criminal forums, sometimes bundled with instructions for filing requests. The Revolut case reads like that warning played out: a mailbox bought from stolen logs, then months of requests nobody questioned. Four years after the Apple and Meta cases, the same class of attack has worked against a company that serves more than 80 million customers, holds a full UK banking license, and in September secured conditional approval to operate as a national bank in the US.

None of that makes Revolut uniquely careless. It makes a narrower point. Scale and regulatory maturity do not close this particular gap on their own. Any organization that holds identity documents and is obliged to answer official requests has the same seam. Most have not been tested on it yet.

Why it matters more if you hold crypto

In August we wrote about the Trezor and Ledger customer data leaks and argued that a stolen shipping address is worth more than it looks, because leaked data becomes more valuable when fields are joined. A phone number alone decides nothing. A phone number plus a recent hardware-wallet order plus the street it shipped to is a qualified list of confirmed holders.

The Revolut file is that argument with the joining already done. Nobody has to cross-reference anything. The dossier arrives complete, and it carries two things the hardware-wallet leaks did not: a verified document with a matching selfie, and a financial history. The attacker even claims the 680 names were shortlisted through analysis of on-chain wallet activity before a single request was sent. That is unverified, but it fits ZachXBT's read of the target list, and it inverts the usual order: the wallets were found first, the names came after.

The document and selfie are the standard material for identity verification. With both in circulation, an attacker has unusually strong material for impersonation and for more convincing social engineering. They do not automatically defeat modern verification controls. They are far more useful than contact details alone.

The transaction history matters for a different reason. On-chain transactions are public and permanent. What was private was the link between them and a legal name. Where a Revolut statement records transfers to or from external wallets, that link is now in someone's hands, and those addresses can be watched. A large incoming transfer months from now will be visible to a person who already knows where you live. CertiK counted 52 verified physical attacks on crypto holders worldwide in the first half of this year, a third more than in the same period of 2025. When a known crypto holder is tied to a home address and evidence of meaningful activity, the physical risk increases.

What comes next

Every large identity leak has been followed by a wave of contact that uses it. Ledger customers were still receiving phishing letters by post years after the company's 2020 breach. There is no reason to expect this one to behave differently, and two reasons to expect worse: the data is richer, and the incident itself is now the pretext. An expired countdown changes none of that. Whether or not a sale happened on Thursday, the files were already outside Revolut's control on September 11.

The first messages will reference the leak directly. Someone claiming to be Revolut, contacting affected customers with a link to verify their identity or secure their account. Then a second circle: parties who are not Revolut but know you use it. A wallet provider warning about exposure. A regulator with a case number. A law firm assembling claimants. A service that scrubs your data from the leak for a fee. Somewhere in that sequence, for anyone whose statement shows crypto, comes the line that moves money: "Your funds are at risk; transfer them to this secure address while we sort it out." Months later, recovery services will approach the people for whom that worked.

Not everyone contacted will be on the list. Scammers do not restrict themselves to the actual affected group. The coverage makes the pretext plausible for any Revolut customer, and few people can say with confidence which of their providers have had an incident this year.

"A password has a half-life of minutes once you know it leaked. A passport scan and a transaction history have a half-life of years. The people who buy this kind of data are not in a hurry. The correct assumption is that it will be used, and that it will be used later."

Stefan Lauer

What to do now

If you received the notification. Assume everything in it is in circulation. Where your issuing authority allows, replace the document; a new passport number makes the old scan a worse tool. Most countries run a fraud-prevention register or credit-bureau flag that raises the bar for opening accounts in your name. Watch for credit applications or SIM changes you did not initiate. Revolut has said it is supporting affected customers; ask in the in-app chat what that includes.

Treat knowledge as proof of nothing. Someone who knows your date of birth and your last few transactions has read a file. That is all it proves. Legitimate institutions do not establish their identity by reciting yours.

Do not act on inbound contact. Not an email, not a call, not a letter, not a QR code. Close it. Open the app yourself, or the site from a bookmark you saved earlier, and look for the message there. If Revolut needs something from you, it will be visible when you log in. This one habit defeats nearly every scenario above.

Protect the phone number. It is the reset channel for most of your accounts, and it is in the file. Ask your carrier for a port-out PIN or SIM lock. Move two-factor codes off SMS and onto an authenticator app or hardware key wherever the service allows it.

Check the address before you send. The scenario that moves crypto is the "secure wallet." Before sending funds to any address someone else gave you, look at it. SimpleSwap's Address Check, available to registered users in the Customer Account, screens a wallet address through third-party services and returns a risk level with the connections it found. It is context rather than a verdict. It will not catch every bad address, and it does not replace asking who wants the transfer and why. An address that comes back high-risk is a conversation you can end.

Read the map before you need it. These patterns are covered in the SimpleSwap Safety Academy and in the Know the Scam series. They are more useful to read in advance than looked up after a message lands.

Your money, your responsibility

None of the above depends on what Revolut does next, or on what Italian prosecutors eventually establish. The official account of what happened may differ in detail from what is public today. The files are already out, and no company can recall them.

What remains under your control is the value an accurate detail holds for a stranger who has it. Every scam in this series runs on borrowed credibility, and leaked data is how that credibility is bought. The next message that arrives, knowing your correct name and your last transaction, is evidence that a file has leaked somewhere. It is not evidence of who sent it. Holding that distinction is most of the work.

 

This article is for educational purposes only and is not financial or security advice. Tools and services named here are examples, not endorsements. SimpleSwap is a self-custodial swap aggregator; use of the service is subject to its Terms of Service, including jurisdictional restrictions. SimpleSwap's only official domain is simpleswap.io.

Information as of the morning of September 18, 2026. The story is still developing, and figures, timelines, and official statements may change.

 

How do you rate this article?

1


SimpleSwap
SimpleSwap Verified Member

SimpleSwap is a self-custodial multi-source swap aggregator that helps users exchange crypto wallet-to-wallet with more privacy and control. It supports swaps across 20+ liquidity providers and 2,800+ assets, combining CEX and DEX liquidity under the hood


SimpleSwap Blog
SimpleSwap Blog

SimpleSwap is a self-custodial multi-source swap aggregator that helps users exchange crypto with more privacy and control, without comparing providers and routes themselves. It supports direct wallet-to-wallet swaps across 20+ liquidity providers and 2,800+ swappable assets, combining liquidity from well-known CEX and DEX sources under the hood.

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?