Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom – SecurityWeek

September 17, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: securityweek.com

Threat Risk: High
Victim: Revolut and the Italian Ministry of the Interior
Incident: Data breach facilitated by the impersonation of government agencies via compromised email accounts.
Impact: Exfiltration of personal and financial data from 680 high-profile customers and 147GB of law enforcement data.
Attacker: IAmNotAVillain
Analysis: Attackers leveraged infostealer logs to hijack a legitimate government email account, allowing them to send fraudulent legal requests that Revolut fulfilled without proper verification. The specific targeting of ‘crypto whales’ suggests a financially motivated actor seeking high-value targets. This incident underscores the danger of relying solely on email authenticity for sensitive data disclosures.
Recommendations: Implement mandatory out-of-band verification for all law enforcement and government data requests.; Deploy robust monitoring for compromised organizational credentials within infostealer logs.; Enforce strict multi-factor authentication (MFA) across all government-facing communication channels.
Source: SecurityWeek

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *