Trusted coverage, investigations and public commentary on the September 2026 Revolut data-extortion situation, collected in one place. Claims by the group behind the leak are unverified and labelled as such. Vote a link up if it is worth reading; suggest one at the bottom.
Revolut confirms it disclosed customer data to an unauthorised third party after fraudulent information requests sent from a legitimate government email domain. The company says its own systems were not hacked.
Coverage of Revolut's statement describing a 'sophisticated external impersonation scam' that used a government agency domain to submit fraudulent data requests, affecting a limited group of customers.
Independent crypto-security researcher ZachXBT publicly flagged the breach via Telegram on 12 Sep, sharing a customer notification. Link goes to his verified channel, not one specific post.
An explainer pulling together what is established and what is still unverified — the scope, the data types exposed, and the open questions around the government-email vector.
Reporting that the leak may trace back to compromised Italian government accounts, with the certified PEC email channel allegedly abused to request customer records.
Italy is reported to be investigating a hacked government PEC mailbox said to be linked to the fraudulent Revolut data requests.
Summary of the attacker's claim to have breached an Italian government email account in order to obtain Revolut customer records. The claim remains unverified.
The threat actor claims the breach is larger than reported and alleges access to Italian law-enforcement systems. These are the actor's own claims and are not independently confirmed.
A threat-intelligence write-up examining the extortion site and the actor's claims, including the ransom demand and the disputed 'impersonator' sample.
Report that the breach targeted around 680 Revolut customers described as high-value crypto holders ('whales'), whose identity documents and transaction histories were exposed.
Report that individuals in the crypto industry are being personally blackmailed using the stolen KYC and transaction records tied to the breach.
Citing the Financial Times, reports that the attackers cut the ransom to about $3M and set a 24-hour deadline to sell 680 customer files.