Revolut Leaker Claims Italian Police Systems Breach Too
Days after Revolut confirmed it handed customer data to an attacker impersonating a government agency, the group behind that leak site, IAmNotAVillain, has escalated its claims dramatically, alleging it also compromised multiple Italian law enforcement departments and used those systems to send the fraudulent requests to Revolut.

None of the new claims, the system compromise, the 147GB figure, or the six-month operation window, have been verified by Italy’s Interior Ministry, national cybersecurity agency, or police as of publication. Everything below is what is being claimed, sourced to the actor’s own leak site and a single X account, Cyber Digest, that says it is in direct contact with them.

What’s Actually Being Claimed

  • 147GB of Italian law enforcement data: a folder screenshot shown by the actor lists roughly 86,999 files across 5,223 folders, reportedly including internal documents, calendars, and personal chat logs, among them a claimed exchange between a federal officer and his wife
  • Six-month operation: the actor says compromised Italian systems were used to route fraudulent data requests to Revolut over that period
  • 31 countries affected: the leak site claims Revolut data spans residents of Cyprus, Portugal, Germany, Spain, Bulgaria, Czechia, Romania, Poland, Malta, Norway, Sweden, Italy, Greece, Netherlands, Latvia, Austria, Belgium, Estonia, Croatia, Ireland, Slovakia, Finland, Lithuania, Hungary, Denmark, Turkey, Monaco, Luxembourg, the Bahamas, Slovenia, and the UK, with most volume from Switzerland and France
  • A named high-profile target: the actor claims the data includes Barcelona forward Georges Mikautadze, unconfirmed by the player or the club

The Detail Most Coverage Is Missing: A Turf War

The leak site itself explicitly disputes being “the Revolut hacker.” Its own notice states an impersonator, described as someone who used to work with the group, took a small data sample they had handed him and is now separately claiming credit for the full breach. IAmNotAVillain says it can prove the originals, volume, internal conversations, and the source companies, and is warning others not to deal with the rival claimant, calling him a scammer. That means at least two parties are now publicly fighting over ownership of stolen Revolut data, which should lower confidence in any single figure or timeline until independent forensic confirmation exists, not raise it.

Why the Jurisdictional Claim Matters Most

Revolut has already confirmed the core fact: customer data was released after requests arrived from an email address on an authentic government domain. What remains entirely unconfirmed is whether that domain access came from compromising Italian law enforcement infrastructure specifically, as opposed to a single mailbox, a phishing compromise of one employee, or a different country’s systems entirely. Italian outlets reporting this story have been explicit that archive size, operational persistence, and the Italian scope are, so far, claims made by the threat actor alone. The EU’s reluctance to act on the North Cyprus leak over a GDPR jurisdictional gap shows how claims spanning multiple European legal systems can stall accountability regardless of the volume of data involved. If a national police infrastructure was genuinely used as a pass-through for a private fintech’s KYC data, that is a materially different regulatory and criminal matter than a single spoofed inbox, and Italian authorities have given no indication yet which one this actually is.

Follow us on Bluesky, LinkedIn, X, and Telegram to Get Instant Updates