The cyberattack that led Revolut to hand sensitive customer information to scammers may have been broader and longer-running than initially understood, according to new claims from the hacker behind the operation.
The attacker, using the name “IAmNotAVillain,” claims to have maintained access to several Italian law enforcement departments for approximately six months. During that period, the hacker allegedly used compromised government systems to send requests for private customer information to Revolut.
These claims have not been independently verified, and Italian authorities have not publicly confirmed that the systems described by the attacker were compromised.
What is confirmed is that Revolut disclosed customer information after receiving fraudulent requests sent from an email address on a legitimate government agency domain. The fintech company has described the incident as a “sophisticated external impersonation scam.”
The company initially said a limited number of customers were affected without providing a figure. More recent reporting indicates that Revolut has contacted 680 customers following its initial investigation.
Information disclosed to the attackers included highly sensitive identity and financial records. Depending on the affected customer, this could include names, addresses, identity documents, verification photographs, bank account information and transaction histories, including cryptocurrency activity.
Revolut maintains that attackers did not compromise its own systems and that customer funds remain unaffected.
The hacker is now making substantially wider claims about the operation. IAmNotAVillain says 147GB of information was obtained from Italian authorities, including internal documents, calendars and personal files. The attacker also claims to possess private communications taken from law enforcement systems.
None of those claims establishes that 147GB of data came from Revolut. Instead, the alleged archive is said to originate from compromised Italian government systems.
The attacker further claims that Revolut customer records were obtained across numerous countries, with most of the data relating to customers in Switzerland and France. Other countries allegedly represented in the stolen information include Germany, Spain, Italy, Poland, Sweden, the Netherlands, Ireland, Lithuania and the United Kingdom, among others. Those geographic claims have also not been confirmed by Revolut.
The incident appears to have exploited trust in official government communications rather than a vulnerability inside Revolut’s banking infrastructure. After detecting the fraudulent activity, Revolut blocked the email address and alerted the relevant government agency, law enforcement, data protection authorities, and financial regulators.
The UK’s Information Commissioner’s Office is investigating after Revolut reported the incident. Meanwhile, the hacker has threatened to publicly release stolen customer information unless a ransom is paid.
