Revolut's breach began with a stolen government password

Revolut CEO Nik Storonsky Interview
Nikolay Storonsky, CEO of Revolut
Al Drago/Bloomberg
  • Key insight: The attacker picked Revolut's Lithuanian subsidiary because European law obliges it to answer cross-border evidence demands, targeting the compliance obligation itself rather than working around it.
  • What's at stake: Every U.S. bank runs a legal and compliance queue that answers subpoenas and government records requests, and it typically sits outside the security team's view entirely.
  • Expert quote: "Just as we don't grant someone access to a bank vault simply because they arrived in a marked police car, legal data requests coming through certified channels must undergo zero-trust verification," said Anu Liinev of Veriff.

Overview bullets generated by AI with editorial review.

Processing Content

Attackers pried hundreds of customers' passports out of Revolut earlier this year by compromising Italian government email accounts.

The hackers used stolen credentials to log into real government accounts on a certified email channel built and maintained by the Italian state.

They emailed phony legal requests over this legitimate channel, so they passed every technical check a bank can run on an email. Revolut answered the requests over several months.

The London-based fintech confirmed Saturday that an unauthorized third party stole customer records by sending fraudulent information requests from a legitimate government agency's email domain.

The attackers told the Financial Times that they posed as Italian law enforcement and said they needed the records for ongoing investigations. The attackers told the news outlet that they used blockchain analysis to pick out Revolut customers with large cryptocurrency holdings.

Revolut replied with passports and driver's licenses, the verification selfies customers took to open their accounts, bank account numbers, account statements and full transaction histories, including cryptocurrency activity.

"Revolut recently identified a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information," a Revolut spokesperson told American Banker.

The company blocked the address on detection and alerted the agency, law enforcement, data protection authorities and financial regulators, according to the statement. Revolut has not said how it detected the fraud.

The incident reached only about 680 customers, none of them in the United States, according to a person close to the company. A group calling itself IAmNotAVillain published a $3 million ransom demand on its own website Wednesday.

So, the attack was small, but it defeated a process every U.S. bank runs.

Legal and compliance departments answer subpoenas, court orders and emergency requests for customer records routinely. The safeguards a U.S. banker would use to check that such a request is genuine would not have caught the one Revolut answered.

It's not just hypothetical; the FBI warned in 2024 that criminals were sending banks and other companies fraudulent emergency data requests from compromised government email accounts.

The previous year, Federal prosecutors in Brooklyn charged a man with running that play against American companies. The man took over a Bangladeshi police official's email account and used it to ask U.S. platforms for their users' personal details.

How a stolen password became months of lawful-looking requests

Someone had stolen credentials for accessing Italy's government certified-mail accounts before Revolut received any phony government requests.

Hudson Rock, a cybersecurity intelligence firm, said Tuesday that it reviewed images of the exchange that show the attackers' correspondence coming from addresses on the Italian Ministry of the Interior's certified-mail domain.

Hudson Rock also found roughly 300 compromised logins for that domain already sitting in its own database of stolen credentials.

That database is built out of infostealer logs; these are programs that infect a computer and copy every password saved in its browser. The files they produce get bought and sold in bulk on criminal markets. Hudson Rock collects them and sells companies access to what it finds.

The company does not say when the Italian credentials were taken, or whether the attackers used any of the ones it holds.

It does say it is "highly unlikely" the attackers infected Italian government employees themselves and more likely that they bought logs somebody else had already collected, according to the post.

A working login is all it takes to send mail through Italy's Posta Elettronica Certificata system, a state-regulated email service. The Financial Times reported that the requests reached Revolut through that system and that the exchanges ran for months.

The attackers have also given an account of the campaign to Duel, a group that says it investigates cybercrime and published what the attackers said in a thread on X.

The hackers told Duel they settled on Revolut Bank UAB, the company's Lithuanian subsidiary, because it is obliged to answer a European Investigation Order. That is a cross-border demand for evidence that European Union member states can send one another.

On one occasion, by the same account, the attackers sent a document in the wrong form, and Revolut's staff explained how to correct it rather than treating it as a reason for suspicion.

Stolen government mailboxes are already for sale here

The FBI's November 2024 notification on fraudulent emergency data requests documented an illicit forum listing "High Quality .gov emails," including U.S. credentials, and a seller claiming to control government email accounts in more than 25 countries.

Read more:

That notification also documented an attempt against a financial services company; a criminal posted photographs on a forum in March 2024 of a fraudulent request sent to PayPal.

That fraudulent request cited a child-trafficking investigation under a treaty for cross-border evidence and carried a case number and a legal code, according to the notification. PayPal refused the request.

Because these demands arrive as part of a legal process, they typically go to the lawyers rather than to the security team.

"At most banks, government data requests land with legal or compliance, not information security," Denis Calderone, chief technology officer at Suzu Labs, a cybersecurity consultancy, told American Banker.

"The security team typically has no visibility into what data leaves through that channel because it's treated as a legal process, not a data transfer," he said.

Ownership of that queue "is never standardized across the industry," said Jason Brown, director of customer advisory and counter fraud lead at the threat-intelligence firm iCOUNTER, who ran one himself as director of risk operations at a payments company.

The written proof regulators require can also be forged

The interagency information security guidelines that bind every national bank tell banks to consider controls "to prevent employees from providing customer information to unauthorized individuals who may seek to obtain this information through fraudulent means."

The OCC, which gave Revolut conditional approval for a national bank charter earlier this month, said in the charter letter that it requires the new bank to comply with these guidelines (and others) before the agency grants final approval.

The OCC also told banks a year ago to demand written proof from a government agency before handing over a customer's financial records.

A bulletin the office issued in September 2025 says a financial institution "generally may not release a customer's financial records unless the government authority certifies in writing that it has complied with its obligations under the RFPA."

However, that written certification is not a sign that the request is legitimate because an attacker could forge it.

"A compromised mailbox can forge that certification as easily as it forges the request," Brown told American Banker. "The document is only as good as the sender behind it."

The control that would have caught it

Whoever sent the request controls the authentication signals, which is why the verification that works has to come from outside the message, according to Brown.

"A workable independent step verifies the requester, not the request," he said. "Confirm the named investigator through the agency's published main line, not a number or address supplied in the correspondence itself."

Risk, compliance and legal need to agree on that step in advance, Brown said, "because in the moment, it will feel like friction on a lawful request."

Making that call requires something most banks have not built. Calderone called it a verified contact registry of known-good phone numbers and points of contact at the agencies a bank deals with, "independently sourced and never pulled from the incoming request."

"A request for basic account records as opposed to a request for passport scans, KYC selfies and full transaction histories are not the same thing and shouldn't go through the same approval gate," Calderone said.

Banks already know how to do this with money. Wire transfers get dual authorization, callback verification and dollar thresholds that trigger escalation, "because everyone understands a wire is sensitive and the loss is immediate," Calderone said.

Customer records leaving the building never got that treatment because "a bad payment is the bank's loss the same day, while released data becomes someone else's fraud months later somewhere else," according to Eric Capuano, who runs the security operations center at Black Hills Information Security.

Certifying delivery "is not the same as identity and authority verification," said Anu Liinev, fraud optimization manager at the identity verification company Veriff.

"Just as we don't grant someone access to a bank vault simply because they arrived in a marked police car, legal data requests coming through certified channels must undergo zero-trust verification," meaning checks that assume nothing about the sender, she said.

Calderone's advice to a bank's legal intake team was to find the gap in the process for handling legal requests before someone else does.

"Stress test the procedure by running a tabletop exercise around this exact scenario," he said. "Walk a fraudulent government data request through your entire intake process and see where it gets caught, or doesn't."


For reprint and licensing requests for this article, click here.
Cyber Security Regulation and compliance Fraud Data security Technology
MORE FROM AMERICAN BANKER
Load More