Revolut has confirmed a data breach in which an unauthorized third party accessed sensitive customer information by submitting fraudulent requests through an email address using a legitimate government agency’s domain This article explores agencies compromised revolut. . Revolut claimed that biometric facial telemetry was not involved or compromised.
Financial information may have included account statements with IBANs, account status, opening dates, and wallet reference numbers, as well as withdrawal records and complete transaction histories, including Bitcoin activity. Separately, International Cyber Digest reported claims from a threat actor known as “IAmNotAVillain,” who stated that multiple Italian law-enforcement agencies had been compromised and that the Revolut operation spanned six months.
A screenshot circulated under the alleged actor’s watermark appears to show multiple archives named “Document Revolut,” email correspondence using an Italian certified-email address, and one extracted folder containing 688 files across 204 folders. While the image is consistent with the broader allegation that formal law-enforcement channels were repeatedly abused, screenshots alone cannot establish authenticity, provenance, completeness, or the sender’s identity. Despite its systems not being breached and customer funds remaining unaffected, the assurance provided does not eliminate the downstream risk associated with disclosing durable identity documents and detailed financial records.
High-risk disclosures should require independent verification through a previously registered agency contact, case-number validation, requester authorization checks, dual approval, anomaly detection across repeated requests, and tamper-evident audit logs.











