Features 21.09.2026
The Revolut breach: what we know so far
As data breaches go, a recent incident at Revolut stands out for several reasons
Features 21.09.2026
As data breaches go, a recent incident at Revolut stands out for several reasons
As data breaches go, a recent incident at Revolut stands out for several reasons. Although reports suggest just under 700 customers are affected, they are believed to be high-net-worth individuals specifically singled out through blockchain analysis. Their personal and financial data ended up in the hands of a cyber-extortion group not because the hackers breached a customer database, but because the bank was tricked into responding to a fraudulent compliance request.
Fortunately, a good cyber-insurance policy should still pay out even in such unusual circumstances.
At the time of writing, Revolut has done little but to confirm its own systems remain unaffected by the incident and that victims and relevant authorities have been contacted. What we know so far comes from a mix of threat actor statements to reporters and cybersecurity research.
The group, known as “IAmNotAVillain”, appears to have targeted Revolut Bank UAB, Revolut’s Lithuanian-regulated entity, because the latter is legally obliged to respond to European Investigation Orders. The threat actors first compromised official Italian Ministry of the Interior email accounts using infostealer logs. Then, posing as law enforcement, they made multiple requests for customer data over a six-month period. To maintain persistence and avoid detection, the group apparently added a recovery email address, monitored inboxes continuously, and deleted outgoing and incoming messages over this period.
“The lesson is to remove processes where sensitive information is shared via email,” Nick Harris, CISO, Assured
Revolut reportedly handed over a treasure trove of data including full names, dates of birth, occupations, postal and email addresses, phone numbers, identity documents, verification selfies, IBANs, account statements, withdrawal records, wallet reference numbers, and full transaction histories including Bitcoin activity. Having released snippets of data online, the group is reportedly asking for 6,000 Monero (XMR), or roughly $3m, although Revolut claims not to have received a direct demand.
This type of attack is not new per se. The FBI warned in November 2024 that compromised government email accounts were being actively sold and used for fraudulent emergency data requests. However, the targeting of crypto owners is a concern, especially as the inclusion of their home addresses could put them in physical danger.
There are several takeaways for cybersecurity leaders, including the need for comprehensive staff training alongside advanced email detection software capable of uncovering anomalous behaviour, says Assured CISO, Nick Harris.
Additional best practices that may have mitigated the breach include data minimisation policies to restrict what is shared with third parties. Harris argues that organisations may also want to review their trusted communications channels in light of the breach.
“The lesson is to remove processes where sensitive information is shared via email,” he says. “If done through a secure method which requires the end user to authenticate, it won’t end up in the wrong hands; nor will it remain in a mailbox to be found if there is a BEC.”
There are also lessons to be learnt on the Italian side. “Detections of account compromise, threat intel to uncover the existence of infostealer logs, and conditional access policies limiting sensitive systems and mailboxes to only trusted devices would have helped, alongside alerting for unusual sign-ins,” Harris explains.
On a more positive note, a robust cyber-insurance policy will cover the various financial liabilities Revolut is now exposed to, according to Assured senior cyber broker, Caspar Rogers.
“A good cyber policy should not require the insured’s network itself to have been compromised before privacy-related cover responds” Caspar Rogers, Senior Cyber Broker, Assured
“A good cyber policy should not require the insured’s network itself to have been compromised before privacy-related cover responds,” he explains. “The relevant trigger should extend to the unauthorised disclosure of personal or confidential information, subject to the specific wording.”
Rogers says that insureds should also expect to be covered for:
However, the insurance landscape is constantly evolving. That means the bare minimum cybersecurity controls expected of policyholders may change over time.
“From an underwriting perspective, insurers may increasingly look at out-of-band verification procedures for sensitive information requests: for example, independently verifying the requesting authority rather than relying solely on the originating email address,” Rogers concludes.
Threat actors don’t always need to break into corporate systems if they can simply persuade an employee to give them what they want.