Cybersecurity & Data Protection Blog | CyberGrant

The Revolut case: a ransom demanded from a company never breached

Written by Valerio Pastore | Sep 29, 2026, 9:00:15 AM

Six thousand XMR within twenty-four hours, a public countdown, fewer than seven hundred customers involved. The fintech's systems held, and no account was touched. The ransom came anyway. What is being held hostage here is trust, and it works only because those files left the building readable.

Key takeaways

  • Revolut was not breached. Records belonging to roughly 680 European customers were handed over in response to a law enforcement data request sent from a hijacked Italian government mailbox on the pec.interno.it domain, traced to the Reggio Calabria prefecture, dated July 24, 2026.
  • The group calling itself iamnotavillain demanded 6,000 XMR, about $3 million, with a public 24-hour countdown, and never contacted the bank directly.
  • Systems intact, accounts intact, zero downtime. The IBM Cost of a Data Breach Report 2025 found that 86% of breached organizations suffer operational disruption. Here that line reads zero, and the bill still arrives.
  • The 2026 Clusit Report records a 37% increase in incidents against the government, military, and law enforcement sector compared with 2024. In Italy that sector is now the single most attacked, at more than 28% of all incidents.
  • NIS2, transposed in Italy as Legislative Decree 138/2024, and DORA, Regulation (EU) 2022/2554, place accountability on senior management. The organization holding the data answers for how it protected it, even when the compromise happened upstream.
  • A document encrypted at creation, unreadable once it leaves the perimeter of whoever produced it, would not have stopped that mailbox from being compromised. It would have left the countdown with nothing to sell.


A public countdown, and no system breached

"6,000 XMR / $3,000,000, or all the data gets sold." The group signing itself iamnotavillain posted the deadline on its own site, and pushed the documents through Telegram, instead of negotiating privately the way extortionists normally do. Revolut said no one had approached it directly. The countdown stayed online.

The systems held, and operations never stopped for a minute. No customer account was touched. The data left anyway, through the front door. The company received a request for customer data from an address that genuinely belonged to a public authority's mail domain, with valid credentials, and forwarded the information the way the GDPR requires when the request comes from an authority with a binding order. It did what it was supposed to do.

The legitimate request became the delivery channel

Financial and cloud platforms handle dozens of emergency data requests a day. The procedure is routine, expected, documented. The attack never had to get around it. It used it as the delivery mechanism.

According to documents released by the attackers and reporting in the Italian press, the sending address was a certified government mailbox, known in Italy as PEC, traced to an office of the Reggio Calabria prefecture, with a send date of July 24, 2026. The same sources describe roughly six months of undetected access to institutional systems. That figure is unconfirmed: on September 18, in Parliament, the Italian government acknowledged the mailbox compromise without endorsing that duration. Italy's Agency for Digital Italy has said it is seeing more compromised certified mailboxes, and the pattern holds elsewhere: the 2026 Clusit Report records a 37% increase in attacks on the government, military, and law enforcement sector compared with 2024. When the link that gives way is a public institution, the exposure lands on every organization legally obliged to talk to it.

Business continuity that downtime does not measure

The IBM Cost of a Data Breach Report 2025 found that 86% of breached organizations experience operational disruption. In the Revolut case that line reads zero. The disruption sits somewhere else: in the executive hours pulled off the business to manage the crisis, in customer notifications, in the exchanges with the cybercrime police unit, the data protection authority, and financial regulators, in the press coverage that tracks every hour of the countdown.

The same report files lost revenue from system downtime, customer churn, and reputational damage together under "lost business," because they usually arrive together. Here they arrived separately. No downtime at all, and a bill to pay regardless.

A mismatch that says everything

Fewer than seven hundred customers were affected, across several European countries. Revolut has passed five million customers in Italy alone, where as of May 2026 Milano Finanza ranked it fifth among the country's banks by number of account holders. Between the records that got out and the damage to the brand there is no arithmetic proportion at all.

The explanation lies in what those records are: passports, driver's licenses, identity documents, verification selfies, full transaction histories. Material that lets someone open accounts in another person's name, and that no revocation call brings back once it is out. What gives the extortion its value is that those documents are readable. The count barely matters.

The bill goes to whoever kept the data in the clear

NIS2, transposed in Italy as Legislative Decree 138/2024, and DORA, Regulation (EU) 2022/2554, moved accountability onto senior management. Both assume the same chain: the organization that handles the data answers for how it protected it, even when the incident starts upstream and outside its control. Revolut was not intruded upon, it answered a formally legitimate request, and its name sits at the top of every article about the case. The same mechanism is open to any company that exchanges documents with a public administration, with a supplier, or with a law firm. Your counterparty's security posture is invisible from the outside, and good faith stops protecting a file the moment it leaves.

Article 32 of the GDPR requires measures appropriate to the risk. For many organizations that has meant access controls and channel encryption, with the content reverting to plaintext the moment the channel opens. A document encrypted at origin, unreadable even after it leaves the perimeter of whoever produced it, would not have prevented that mailbox from being compromised. It would have left the countdown with nothing to sell.

For years the question for anyone designing security has been how to keep attackers out. The Revolut case puts a different one in front of the board: what is left in an extortionist's hands when the data walks out through a door the company was legally required to open. As long as the answer is "perfectly readable files," public extortion will keep sending the bill to companies that made no technical mistake at all.

Update, September 25, 2026

On September 18, Undersecretary of the Interior Wanda Ferro confirmed the mailbox compromise on the floor of the Chamber of Deputies. Italy's national cybersecurity agency, through CSIRT Italia, verified the attack by analyzing a sample of the fraudulent emails supplied by Revolut itself, and put the number of Italian customers involved at eight out of 680. The deadline expired with no payment. Around September 23 the group opened a data leak site on Tor and began demanding ransom from individual customers directly, claiming to know their names, addresses, and crypto holdings. The first extortion failed and the material still produces value. That is the working definition of data that stayed readable.

Valerio Pastore

Founder & CTO, CyberGrant Inc.

Frequently asked questions

What is an emergency data request, and why is it a risk vector?

An emergency data request is how a judicial or law enforcement authority asks a service provider for a user's data, often under an expedited procedure with short response windows. Financial and cloud platforms handle dozens a day. The risk is not the procedure, which is legitimate, but the fact that authentication rests on the sender's address. Compromise that mailbox and the attacker does not have to break anything, they only have to ask. In the Revolut case the request came from a certified government mailbox on the pec.interno.it domain, traced to the Reggio Calabria prefecture, dated July 24, 2026.

How do you protect a document you are legally required to hand over?

Encrypt it at creation, not at the moment you send it. File-centric protection binds the key to the file rather than the channel: the document stays unreadable after delivery, and access runs through a permission the owner can revoke, track, or expire. The question changes. Not "who may receive this file," but "who may open it, when, and for how much longer." With FileGrant, post-share revocation and the audit trail keep working on copies that already left the organization.

Is channel encryption enough for data shared with government bodies?

No, and the Revolut case shows why. TLS 1.3 and certified email protect the transmission and prove sending and receipt. They say nothing about whether the request itself was legitimate, and nothing about the content once it lands. The file becomes readable again the moment the channel is decrypted. From that point there is no protection left: no revocation, no control over copies or forwards. Article 32 of the GDPR requires measures appropriate to the risk, and for identity documents the risk does not end at delivery.

What do NIS2 and DORA require when the incident starts upstream?

Both place accountability on the senior management of the organization handling the data, not on whoever caused the upstream compromise. NIS2 was transposed in Italy through Legislative Decree 138 of September 4, 2024, in force since October 16, 2024, with operational measures due by October 2026. DORA is Regulation (EU) 2022/2554, applicable to the financial sector since January 17, 2025. In practice, the security posture of suppliers and institutional counterparties has to be treated as your own risk, documented and measurable.

How do you verify a data request that arrives from a genuine mailbox?

Out of band. Confirm the request on a channel independent of the one it arrived on, typically an official contact pulled from the authority's public register rather than from the message itself. Alongside that: correlation logging, since a mailbox issuing requests at an unusual rate is a signal; dual control on any bulk release of identity documents; and a standing rule that sensitive data never travels as a readable attachment, not even inside a certified channel.

What is the difference between perimeter DLP and file-centric protection?

Perimeter DLP inspects outbound traffic and blocks what it recognizes as anomalous. In a scenario like Revolut's it has nothing to block: the request is legitimate, the user is authorized, the channel is the expected one. File-centric protection starts from the opposite assumption. The file is leaving regardless, so it has to leave already useless to anyone not cleared to open it. Encryption at creation, automatic classification, RBAC, revocation, and an audit trail that travel with the document outside the network.

How does file-centric protection fit with SharePoint, OneDrive, and email?

It sits alongside them rather than replacing them. Content stays where it is and people keep working in the same tools: the encryption and policy layer applies to the file, leaving libraries, permissions, and habits untouched. On the email channel the same principle covers messages and attachments through EmailGrant, a module of FileGrant, which keeps control of the content after it is sent. The goal is not to change platforms. It is to take away an attachment's ability to be read by anyone who intercepts it.