Revolut Breach: 680 Confirmed, the Rest Still Unverified
Since Revolut first confirmed handing customer data to a spoofed government request, and since the attacker escalated to claiming an Italian police systems breach, independent reporting has now confirmed the core mechanics while several dramatic claims circulating on X remain attacker-sourced only.

The Financial Times, ANSA, and Italian outlets have independently verified: 680 customers affected, the request came from the Reggio Calabria prefecture’s certified PEC mailbox, and entry was via infostealer malware on a government employee’s device, not a novel breach of state infrastructure. Italy’s Postal Police have opened a criminal investigation into unauthorised access and computer fraud.

What’s Now Confirmed

  • 680 customers, concentrated in Switzerland and France, had passports, IBANs, addresses, and Bitcoin transaction histories exposed. Revolut’s press office has not confirmed the number publicly; the figure comes from the FT and Revolut sources speaking on background
  • The entry point was an infostealer, not a government-network intrusion. Standard commodity malware compromised a government employee’s device, letting the attacker log into the mailbox, add a hidden recovery address, and silently monitor incoming replies
  • PEC, Italy’s certified email system, carries legal weight equivalent to registered post. Revolut’s compliance team acted on messages that passed SPF, DKIM, and DMARC authentication because they genuinely originated from the real interno.it domain
  • Revolut did apply its one available refusal ground. Documents from a July 24 request covering 198 crypto-wallet hashes show Revolut declined direct disclosure for 169 hashes tied to Revolut Ltd (UK) and 29 tied to a Swiss entity, redirecting the requester to UK mutual legal assistance procedures, and only processed accounts held at Revolut Bank UAB in Lithuania, the entity the fraudulent EIO named

What Remains Attacker-Sourced Only

The claim that the operation ran for five to six months, that the attacker compromised Italian law enforcement systems broadly rather than one office’s mailbox, and that 147GB of internal police material was exfiltrated, are all statements from the threat actor, relayed through intermediary accounts on X and picked up by the FT and CryptoTimes as attacker claims, not independently confirmed by Italian authorities.

Blockchain investigator ZachXBT, who first flagged the notices publicly, assessed the targeting as concentrated on high-net-worth users, consistent with the crypto-hash targeting method, but did not verify the broader Italian systems claim. Named alleged victims circulating in threat-actor posts remain actor-attributed unless confirmed by the individuals or a matching Revolut notice; former Mt. Gox CEO Mark Karpelès is the only person who has publicly confirmed receiving a notice himself.

How the Targeting Actually Worked

The method described by the actor to Duel, that Revolut was fed hundreds of public blockchain transaction IDs and deposit addresses under the fraudulent EIO’s cover and returned full customer files for each, is consistent with the confirmed outcome: a highly targeted set of crypto-holding customers, not a random slice.

Anyone whose wallet address is traceable on public blockchains to a Revolut-linked deposit can be turned into a target this way. Self-custody does not close the exposure once KYC data sits with a regulated intermediary obligated to answer authenticated state requests.

The Regulatory Gap Nobody Is Fixing

EU anti-money-laundering law obligates regulated entities to respond to authenticated state requests and provides no mechanism to verify that the state behind an authenticated request is who it claims to be. Refusing carries fines running into the millions; verifying is functionally impossible under current rules.

The European Parliament’s June 18, 2026 resolution named this exact risk “transnational financial repression,” and the Council of Europe adopted a parallel resolution on June 25 calling for an investigation into remedies. Whether either produces binding change before the next PEC-style compromise, at Revolut or any of the thousands of other FATF-obligated institutions running the same exposure, is the open question this case leaves unresolved.

Follow us on Bluesky, LinkedIn, X, and Telegram to Get Instant Updates