Revolut hacked: Italian police data in criminals' hands, $3 million ransom demanded
A group of hackers has breached the digital bank Revolut, stealing 147 GB of sensitive data, including documents from Italian law enforcement. They are demanding $3 million in ransom.

Cyberattack on Revolut: hackers claim Italian police data
Among the data stolen from the British digital bank Revolut could be confidential documents from Italian law enforcement. This is reported by ansa.it, citing statements from the hacker group called "I Am Not A Villain", which claimed responsibility for the attack via Telegram to the Financial Times.
The group claims to have compromised Revolut's systems over a period of several months, obtaining 147 gigabytes of sensitive data, including internal documents and agent chat messages. Italian authorities are carrying out checks to verify the veracity of the claim.
The ransom demand and the deception method
The hackers, who allegedly acquired data relating to 680 international Revolut customers, have demanded that the bank pay $3 million within 24 hours, threatening otherwise to resell the information to other criminal groups. This is reported by the Financial Times, citing a message attributed to the group.
In messages exchanged with the City newspaper, the cyber pirates explained that they had posed as "an entity of Italian law enforcement" and that Revolut had "cooperated like a 'good boy'". The group shared screenshots of exchanged emails as proof of their claims. The requests, signed as "postal police" and sent from a domain with an internal .it extension, reportedly were made repeatedly over a six-month period before raising suspicion.
Investigations opened between Reggio Calabria and the anti-mafia prosecutor's office
The Public Prosecutor's Office of Reggio Calabria has opened an inquiry into the matter. On the magistrates' desk is an initial report from the postal police about unauthorised access to the prefecture's PEC system. The alleged crime is intrusion into a computer system of public interest.
Investigators have not yet established with certainty whether a computer at the Reggio Calabria Prefecture or the Interior Ministry was compromised, but they believe it was a highly sophisticated operation. Experts are working to determine whether the institutional email was breached or cloned. Through that mailbox, the hackers obtained sensitive data — including passports, identity cards, bank accounts and Bitcoin transactions — of several hundred account holders.
The National Anti-Mafia and Counter-Terrorism Prosecutor's Office has also turned its attention to the matter, becoming active as the breach involves a government entity. Investigators are also monitoring the dark web to verify any potential sale of the stolen information.
The Privacy Authority and Revolut's response
The Data Protection Authority has launched an immediate verification into possible security gaps in the access systems of Italian banking institutions, to ascertain whether there have been other infiltration attempts and to remind banks of more effective internal controls.
From the Authority's offices, a communication was sent to the network of data protection officers at banking institutions, with an invitation to carry out a "prompt verification" of their systems and to contact the Authority immediately if any anomalies are discovered. The Authority has also begun coordinated action with its Lithuanian counterpart — where Revolut has its registered office — for an exchange of information aimed at strengthening action against such breaches. On the Interior Ministry's front, the Authority has acted to establish whether other banks or financial institutions have been involved.
Revolut has meanwhile reassured its customers, stating that "Revolut's systems and customer funds have not been touched".
Source: Google News IT — Crime (it)