Europe’s largest financial technology company has around 80 million customers, operates as a bank in more than 30 countries, and was recently valued at roughly $115 billion. It has the security budget you’d expect from a company like that. And according to reporting by the Financial Times, criminals walked away with the complete identity files of hundreds of its customers — passports, driver’s licenses, the selfies people submit to verify their identity, home addresses, full transaction histories — without breaching a single system.
They asked for it. And the company handed it over, politely, for about five months.
That’s not a joke at anyone’s expense, and it’s not as absurd as it sounds — which is exactly why it’s worth your time. The requests arrived from a genuine government email domain, carried valid authentication, and looked precisely like the law-enforcement data requests a bank receives and answers as a matter of routine. Every technical control worked correctly. The messages really were coming from where they appeared to come from. The problem was that the account behind them had been stolen.
Now the attackers have gone public with a ransom demand and a threat that’s uglier than most. Let’s walk through what’s confirmed, how the con actually worked, and why this specific technique — which security people call authority impersonation — is one of the most dangerous things aimed at ordinary businesses right now.
What’s confirmed, and what’s the attackers talking
As always with extortion stories, the loudest numbers come from the people with the most reason to exaggerate. Here’s the split:
| Reported and acknowledged | Claimed by the attackers |
|---|---|
| The company has acknowledged an incident, notified potentially affected customers, is providing support, and is working with law enforcement and regulators. It describes what happened as a sophisticated external impersonation scam. | A 24-hour deadline and a demand of 6,000 Monero — about $3 million — posted publicly on a site the group created, with the message that otherwise the data will be sold. |
| At least 680 customer accounts were affected, reportedly concentrated in Switzerland and France. | That the campaign ran five to six months, and a separate claim of stealing over 147GB from an Italian law enforcement agency. |
| The company says it has received no direct contact or demand from the group, has not negotiated, and has not paid. | A 60-second screen recording, sent to the Financial Times, appearing to show the files. |
| Italian prosecutors have opened an inquiry; Italy’s privacy regulator has contacted its counterpart in Lithuania, where the bank is registered. | That targets were selected using blockchain analysis to find accounts holding significant cryptocurrency. |
One detail is worth flagging as a reminder of how noisy these situations get. Over the preceding weekend, a competing demand of 10,000 Bitcoin — on the order of several hundred million dollars — circulated under a different name. The group behind the current demand says that was an impersonator who had been given a sample of the data and was falsely taking credit. So we have criminals impersonating a government to rob a bank, and then other criminals impersonating those criminals to claim the credit. Treat every figure in this story that didn’t come from the company or a regulator as marketing.
How the con actually worked
Strip out the crypto and the ransom theatrics and the mechanism is elegant, patient, and completely reproducible against smaller targets. Per the reporting, it went like this:
- They stole a real government mailbox. The attackers compromised an Italian government email system — an address that appears to have belonged to an employee within a national ministry. Not a lookalike domain. Not a spoofed header. The actual account.
- They picked their targets from public data. Rather than asking for everything, they used blockchain analysis — publicly visible cryptocurrency ledgers — to identify which customers held substantial crypto. The victims were selected on merit, from information anyone can see.
- They sent ordinary-looking law enforcement requests. Banks receive legitimate requests for customer information from police and regulators regularly; responding to them is a normal, legally required part of operating. These requests arrived through the correct kind of channel, from a real government domain, with valid authentication attached.
- They asked repeatedly, for months. This wasn’t one request. It was a sustained campaign, reportedly running five to six months, targeting specific named accounts one after another.
- They received exactly what they asked for. The material reportedly includes names, dates of birth, occupations, home addresses, passport and driving licence copies, the identity selfies used for verification, account statements with account and wallet identifiers, withdrawal records, and full transaction histories.
Look at that list of data one more time. That isn’t a password dump or a list of email addresses. It’s a complete dossier on a human being — who they are, what they look like, where they live, what they own, and what they’ve done with their money. It’s the most complete package of information about a person that exists anywhere, and it was assembled by asking politely from a stolen mailbox.
Here’s the part that should make every business owner sit up: every technical control did its job. The domain was legitimate, so domain checks passed. The authentication was valid, so authentication checks passed. There was no malicious attachment to scan, no suspicious link to block, no unusual login to flag, no malware to detect. There was nothing for security software to catch, because nothing was technically wrong. The attack didn’t defeat the security stack — it walked around it entirely, by using a real identity to make a request that a human being then approved. You cannot buy a product that stops this. The only defense is a process.
Authority impersonation is coming for small businesses too
It’s easy to read this as a big-bank problem. It isn’t. The underlying technique — pretend to be an authority whose requests people don’t feel entitled to question — is aimed at small businesses constantly, and it works better on them, because a small business has no legal department to route the request to and no written policy telling the person who opened the email what to do.
You’ll recognize every one of these:
- The tax authority. A letter, call, or email about an audit, a discrepancy, or a penalty, demanding documents or payment. It is the single most effective impersonation there is, because almost nobody feels confident telling the tax office no.
- Law enforcement or a subpoena. “We need records relating to one of your customers.” Most small business owners have never seen a real one, have no idea how to verify it, and are terrified of obstructing an investigation.
- A lawyer. Formal letterhead, a deadline, a threat of consequences, and a request for information or a payment redirect.
- Your bank’s fraud department. Calling you about suspicious activity — and needing to verify some details before they can help.
- A regulator, licensing board, or inspector. Anyone with the power to fine you or shut you down gets compliance by default.
- The boss. The oldest version of this: an urgent email from the owner to the bookkeeper, asking for a wire or a copy of the payroll file. Same psychology, smaller costume.
Every one of these works on the same three ingredients: an authority you don’t feel able to challenge, a reason it’s urgent, and a channel that looks right. The Revolut case is simply the most extreme demonstration of the third ingredient — when the channel is not just convincing but genuinely real, every warning sign a person might normally notice disappears. There is no typo in the domain. There is nothing off about the address. It is, in every checkable respect, the government.
The five-month problem
The detail we keep coming back to is the duration. This reportedly ran for months, request after request, account after account.
Any single request in that campaign was defensible. It looked legitimate, it came from a real address, and responding to it was arguably a legal obligation. The problem only becomes visible when you step back and look at the pattern: an unusual volume of requests, from one source, over an extended period, targeting customers who happened to share a very specific profile. No individual approval was obviously wrong. The sequence was screaming.
That’s a lesson with a version in every business, and it’s the same one we wrote about recently in the context of attackers using ordinary built-in tools: individual events look normal, and only the combination reveals the attack. If nobody is ever looking at the aggregate — how many unusual requests came in this quarter, how many customer records got released and to whom, whether the same outside party keeps asking for things — then a slow, patient campaign has all the time it needs. For a small business this doesn’t require a monitoring system. It requires somebody, occasionally, asking “has anything strange been happening repeatedly?”
What actually stops this
Because there’s no product that catches a legitimate email making a legitimate-shaped request, the defense is entirely about process. All of this is achievable for a business of any size:
- Verify out of band, always, no exceptions. This is the whole game. When a request arrives claiming authority, confirm it through a channel you found yourself — a phone number from the agency’s official website, not the number in the message; a callback to a person whose number you already had. Never verify a request using the contact details the request supplied. That single habit defeats nearly every version of this con, including the one that fooled a $115 billion bank.
- Write down who can release customer information, and what has to happen first. Most small businesses have never decided this, so the answer defaults to “whoever opened the email, under pressure, alone.” A one-paragraph policy — nobody releases customer records without X verifying it, and here’s how we verify — removes the decision from the moment of pressure.
- Make “I need to verify this first” a safe thing to say. The reason these scams work is that people are afraid of seeming obstructive to an authority. Tell your team explicitly: nobody will ever be in trouble for taking an extra ten minutes to confirm a request is real. Legitimate agencies expect to be verified. Criminals hate it.
- Give out the minimum, not the maximum. When you do respond to a legitimate request, answer exactly what was asked, rather than sending the full file because it’s easier. Less data handed over is less data lost when a request turns out to be fraudulent.
- Log what you release, and review it periodically. A simple record of who asked for what and when is what turns an invisible five-month campaign into an obvious pattern. It costs nothing and it’s the only thing that would have caught this one early.
- Remember your vendors face the same con. Someone can impersonate an authority to your accountant, your payroll provider, or your IT company, and walk away with your business’s information. Ask them how they verify requests. It’s a fair question and their answer tells you a lot.
Worth asking about your own business: If an email arrived tomorrow from what appeared to be a law enforcement agency or a tax authority asking for records about one of your customers, who in your business would handle it — and would they know how to verify it before responding? * Is there anything written down about who may release customer information? * Do you keep any record of what information you’ve handed to outside parties? * And does your team know, without doubt, that they won’t get in trouble for slowing down to check?
The uglier dimension
There’s a part of this story that deserves to be named soberly rather than sensationally. The attackers’ public message included the line that if the ransom isn’t paid, the data will be sold and “the blood will be on your hands.” That’s a deliberate reference to physical danger, and the reason it isn’t merely rhetoric is the specific combination of what was taken: the identities and home addresses of people known to hold significant cryptocurrency.
Crypto holders face a category of risk most people don’t: because transfers are irreversible and difficult to trace, there have been real-world cases of holders being physically targeted in order to force transfers. A dataset that pairs “this person has substantial crypto” with “this is where they live and this is what they look like” is dangerous in a way that a leaked password file simply is not. We’re not going to dwell on it, and we’re not going to speculate about what will happen. But it’s a stark illustration of a principle worth carrying into your own business: the harm from a data breach isn’t always financial or reputational. When you hold information about where people live, what they own, or what vulnerabilities they have, the stakes of protecting it go beyond money.
If you’re a customer
The company says it has notified potentially affected customers directly and is providing support, so the first thing to know is that the affected group is reportedly small and specific — hundreds of accounts, mostly in two European countries, selected for cryptocurrency holdings. If you haven’t been contacted, you are most likely not among them.
That said, two things apply to everyone, and they’re the same ones we’ve been repeating through a month of identity-document breaches:
- Expect impersonation attempts referencing this story. Any breach in the news is followed immediately by scams exploiting it — fake “security team” calls about your account, emails offering to check whether you were affected, texts urging you to move funds to a “safe” account. Your bank will never call and ask you to move money. Hang up and call back on the number from the back of your card or the official app.
- Freeze your credit and turn on two-factor authentication if you haven’t. It costs nothing and it’s the baseline for a year in which identity documents have been leaking from every direction.
The takeaway
A company with a world-class security budget lost its customers’ most sensitive information without anyone breaking in. No malware, no exploit, no stolen password on the bank’s side, nothing for a security product to catch. Just a request that looked exactly like a hundred legitimate requests before it, arriving from an address that genuinely belonged to a government, asking a human being to do something that was normally part of their job.
That’s the thing to carry into your own business. The attacks that get past everything aren’t the ones that break your technology — they’re the ones that use your own normal, correct procedures against you. The defense isn’t a better product. It’s a small number of unglamorous habits: verify through a channel you found yourself, decide in advance who can release information and how, make it safe for your people to slow down, give out the minimum, and keep enough of a record that a pattern can’t hide for five months.
That’s exactly what our focused security training builds — not paranoia, but a calm, reliable instinct for the moment when an authoritative-sounding request arrives and the right answer is “let me verify that and call you back.” We teach teams what these cons feel like from the inside, give them a script for the awkward moment, and make verifying second nature rather than an act of courage. A bank with 80 million customers was talked out of its most sensitive files by someone with a stolen mailbox and patience. Your team can be the reason nobody writes that story about you.
Sources: Financial Times original reporting (September 2026), as republished and followed by the Irish Times, SecurityWeek, Euronews, Decrypt, PYMNTS, and others. The company has acknowledged an incident, notified potentially affected customers, and described it as a sophisticated external impersonation scam; it states it has received no direct contact or demand from the group, has not negotiated, and has not paid. The ransom amount, deadline, campaign duration, target-selection method, and claims regarding an Italian law enforcement agency are the attackers’ own assertions as reported, and are not confirmed by the company or regulators. Italian prosecutors have opened an inquiry and Italy’s data protection authority has engaged its Lithuanian counterpart. Individual officials and specific compromised addresses are not identified here.













