www.securityweek.com 17 Sept 2026, 13:57 UTC

Hackers Demand $3 Million From Revolut After Fake Police Requests

Hackers Demand $3 Million From Revolut After Fake Police Requests
CyberSIXT Evidence Panel Source marked as original reporting

HACKERS are demanding a $3 million ransom from Revolut after allegedly obtaining customer information through fraudulent government requests over a period of roughly five months. Revolut previously notified potentially affected users that personal information, including passport details, email addresses, phone numbers and financial information, had been exposed. The company said it had not received a direct ransom demand from the people making the claims.

The attackers reportedly used an infostealer-compromised government employee’s email account to send requests to Revolut Bank UAB, the fintech’s Lithuania-based subsidiary. Revolut is required to respond to legitimate law-enforcement requests, and the hackers allegedly exploited that process by impersonating an official agency. SecurityWeek understands that information belonging to approximately 680 customers, reportedly including cryptocurrency “whales”, was compromised. The threat actor known as “IAmNotAVillain” has threatened to sell the data, while claiming that a former associate also possesses a sample.

In separate communications, the hackers claimed the campaign lasted six months and involved the theft of more than 147GB of data from an Italian law-enforcement agency. Italian police are investigating. The compromised address on pec.interno.it appears to belong to an Italian Ministry of the Interior employee, and Hudson Rock said it was aware of more than 300 compromised credentials associated with that domain. Hudson Rock assessed that the attackers probably obtained existing infostealer logs rather than directly infecting the employees.

View full article

Article by CyberSIXT