The Revolut data breach case, which SpazioCrypto reported on just days ago, has grown considerably more serious. That makes it even more necessary to draw a sharp line between what has been confirmed and what is merely claimed by the individual presenting themselves as the attacker. This update reflects information available as of September 15, keeping the two levels clearly separated. The Revolut breach and its alleged Italian dimension demand careful reading, because conflating confirmed facts with unverified assertions would be both inaccurate and potentially harmful.
On one side sit facts confirmed directly by Revolut and independent journalism. On the other sit statements made by a pseudonymous actor through a third-party channel, none of which have yet been confirmed by any competent authority. Here is what we actually know.

What Revolut Has Confirmed
On September 12, Revolut acknowledged that it received and treated as genuine a set of information requests sent from an email address belonging to the legitimate domain of a government agency, without ever disclosing the agency's name or country. Once the deception was discovered, the company blocked the address used, notified the real government agency involved, informed law enforcement, financial regulators, and data protection authorities, and contacted affected customers directly. According to the Financial Times, notifications were sent to approximately 680 customers, a figure significantly higher than the vague “very limited number” Revolut itself had initially cited.

The data exposed, according to notifications shared publicly, includes full names, dates of birth, occupation, residential address, contact details, identity documents, the verification photograph used for KYC, bank account details, account statements, withdrawal records, and a complete transaction history, including Bitcoin transactions where present. Revolut maintains that its internal systems were not breached and that customer funds were not compromised. The UK Information Commissioner's Office has opened its own investigation, and several observers note the episode could weigh on the company's anticipated IPO, which is expected at a valuation of around $200 billion according to reporting by the Financial Times.

The Italy Claims: What the Attacker Says, and What Remains Unverified
This is where the story demands the most caution. A pseudonymous actor, communicating through an account specializing in cybersecurity news, has claimed to have done far more than steal data from Revolut. According to this source, several departments within Italian law enforcement were compromised, and their systems were allegedly used to send the fraudulent requests to Revolut. The operation against the fintech is said to have lasted approximately six months. The attacker also claims to hold around 147 gigabytes of material from Italian systems, including internal documents, calendars, and personal communications attributed to officers.
Precision matters here. These are, at present, unverified claims, not established facts. Italy's Ministry of the Interior (the Viminale), the National Cybersecurity Agency (ACN), and the Polizia di Stato have not confirmed any breach. The exact size of the alleged archive, the true duration of access, and the real extent of any Italian involvement remain, for now, assertions made solely by the attacker. The accurate framing is not “Italian police were hacked” but rather: the attacker claims to have compromised several Italian law enforcement departments, a claim that competent authorities have not confirmed.
Confirmed vs. Claimed
The distinction that matters. Sources: Revolut, Financial Times, attacker-linked accounts, 2026
- Confirmed: data of approximately 680 customers handed over after requests from a genuine government domain.
- Claimed, not confirmed: compromise of Italian law enforcement departments and 147 GB of material.
- Documented by multiple sources: a ransom demand of 10,000 BTC.
The Extortion Attempt and Published Data Samples
The case has also taken on the shape of a large-scale extortion operation. The individual claiming responsibility has begun publishing data samples on a messaging channel. A specialist outlet that reviewed some of those samples reported they appear to relate to prominent figures in business, sport, and entertainment. The ransom demand stands at 10,000 Bitcoin, a value estimated at between roughly $670 million and $800 million depending on the exchange rate applied, with threats to release additional material progressively if payment is not made. Revolut has not publicly commented on this specific demand.
According to statements made by the attacker, the affected customers come from around 30 different countries, with Switzerland and France identified as the most heavily impacted. These geographical details, to be clear, also remain unconfirmed assertions from the attacker's side, not independently verified by Revolut or by any authority. For completeness, it's worth noting that this type of episode is not entirely new territory for the company: earlier this year, a former employee separately threatened to expose the identifying data of a crypto customer in exchange for a cryptocurrency ransom, a different incident in its mechanics but sharing the same underlying pattern, sensitive data collected by Revolut used as leverage for a crypto extortion.

Why the real vulnerability is not where it appears to be
This is the core issue, and it's what sets this incident apart from a standard data breach. The underlying problem is not simply a well-crafted fraudulent email: it's the entire process by which a financial intermediary verifies the legitimacy of a request coming from an apparent authority. An authentic-looking email domain and automated technical checks that return clean results are not, on their own, sufficient to confirm that the sender genuinely holds the authority they claim, the correct territorial jurisdiction, or the legal right to receive data as sensitive as passports, identity photographs, and complete financial histories.
For requests of this sensitivity, a more reliable verification procedure would ideally require confirmation through an independent channel validated in advance, an official registry, or an institutional contact already on record, rather than relying on the contact details supplied within the request email itself. It's the same underlying principle observed when examining the fake security emails targeting BitBox and Trezor users during the same week this case first surfaced: exploiting an existing trust channel rather than attacking a technical system directly.
The broader picture
This update, regardless of its still-unresolved outcome on several fronts, reinforces a lesson that emerged from the first chapter of this case: in digital finance, security depends not only on the technical resilience of systems, but also, and in this case above all, on the processes used to verify the identities and authorities with which a company interacts every day. A system can remain technically untouched and still produce enormous harm if the human and procedural layer surrounding it is successfully deceived.
For anyone following this story, the practical lesson cuts two ways. First, this incident illustrates how important it is to resist turning every claim by an alleged attacker into an established fact, particularly when the institutions directly involved have yet to confirm anything. Second, the episode reinforces just how attractive the combination of verified identity, KYC documents, and cryptocurrency holdings history is to organized cybercriminal operations. We'll continue tracking this story with the same editorial discipline, updating our account only when verifiable confirmations emerge, not unilateral claims. For a practical guide to protecting your assets in the meantime, see our overview of how to store cryptocurrency safely.




