Béatrice Cossa-Dumurgier, Revolut’s CEO for Western Europe, confirmed the reimbursement plan on BFM TV. She said the company will cover expenses for affected customers needing new ID documents, and clarified that Revolut has not paid any ransom demand, nor received one.
The breach impacted approximately 680 clients, 55 of them based in France. Revolut maintains that its internal systems remained secure throughout and that customer funds were never at risk.
How a Fake Police Email Fooled Revolut
The incident, first disclosed last month, began when hackers gained control of an email address belonging to an Italian government agency. Revolut sent customer data to that address believing it was a legitimate law enforcement request, a routine practice for financial institutions assisting criminal investigations.
Italy’s interior minister, Matteo Piantedosi, addressed the incident before lawmakers on September 30. He confirmed the email genuinely originated from the Reggio Calabria police system, but noted the specific address had never been used for this kind of request before. Piantedosi went further, stating Revolut could have and should have verified
the request with minimal due diligence. A Revolut spokesperson declined to comment on the minister’s remarks.
A Pattern of Scrutiny for Europe’s Biggest Fintech
The breach lands at a sensitive moment for Revolut, now valued at an estimated $115 billion as of October 2026 and holding the title of Europe’s most valuable startup. That scale brings proportionally heavier regulatory attention, and this isn’t an isolated headache for the company’s security team. Revolut has separately faced a reported $3 million Monero ransom demand tied to stolen Bitcoin related data, and the broader regulatory environment for fintechs is tightening regardless, with DORA enforcement intensifying around data sovereignty rules across the sector.
Cossa-Dumurgier acknowledged that government agencies can sometimes be the weak link in these verification chains, while maintaining that Revolut’s own infrastructure held up. That framing puts the blame on the compromised Italian system rather than on Revolut’s own verification process for data requests.
What Affected Customers Should Expect
Revolut has not specified the total financial impact of covering ID replacement costs, nor confirmed how many of the 680 affected clients have actually needed new documents so far. The company says it will assist all of them as needed.
- Revolut covers the cost of new ID documents for all 680 affected clients
- No ransom was paid or demanded in connection with the breach
- Customer funds and Revolut’s internal systems were not compromised
- The breach originated through a hacked Italian government email, not a flaw in Revolut’s own infrastructure
Hashlytics Take
The interesting detail here isn’t the breach itself, it’s who’s being blamed for it. Revolut’s framing leans hard on “government was the weak link,” but Italy’s own interior minister is on record saying Revolut should have caught this with basic verification. That’s not a neutral disagreement, it’s the regulator who oversaw the compromised system publicly contradicting the company’s PR line. For a fintech this size, “we trusted an email because it looked official” is a thin standard when the request involved handing over customer identity data. Covering ID replacement costs is the easy part. The harder question Revolut hasn’t answered is what verification step was actually missing, and why it took a government minister saying so publicly for that gap to surface.
Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates



