Close Menu
moneysguide.com

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    With Rates on the Rise, Lean Into the Financials Sector

    September 19, 2026

    Sandisk Joins the S&P 100 on Monday — the Same Day Nike Leaves It

    September 19, 2026

    5 Things Soaring Diesel Prices Will Make More Expensive

    September 19, 2026
    Facebook X (Twitter) Instagram
    Trending
    • With Rates on the Rise, Lean Into the Financials Sector
    • Sandisk Joins the S&P 100 on Monday — the Same Day Nike Leaves It
    • 5 Things Soaring Diesel Prices Will Make More Expensive
    • FTF: Levered Exposure To High Yield Makes It Avoidable, Despite Lower Duration
    • Revolut’s breach began with a stolen government password
    • Stop Competing For Your Own Customer
    • Ripple Legal Chief Calls for Crypto Unity After CLARITY Act Defeat – Bitcoin News
    • Coinbase Files to List Single-Stock Perps on Apple, Tesla and Nvidia
    moneysguide.com
    • Home
    • Business
      • Company News
      • Corporate Earnings
      • Entrepreneurship
      • Mergers & Acquisitions
      • Startups
    • Cryptocurrency
      • Altcoins
      • Bitcoin
      • Ethereum
      • Blockchain
      • DeFi
    • Economy
      • Global Economy
      • Government Policies
      • Inflation
      • Interest Rates
      • Recession
    • Finance
      • Personal Finance
      • Banking
      • Economy
      • FinTech
      • Investing
    • Forex
      • Forex News
      • Economic Calendar
      • Fundamental Analysis
      • Technical Analysis
      • Trading Signals
    • Investing
      • Dividend Investing
      • ETF Investing
      • Growth Investing
      • Portfolio Management
      • Value Investing
    • Stock Market
      • Asian Stocks
      • Earnings Reports
      • European Stocks
      • IPOs
      • US Stocks
    moneysguide.com
    Home»Finance»Banking»Revolut’s breach began with a stolen government password
    Banking

    Revolut’s breach began with a stolen government password

    AdminBy AdminSeptember 19, 2026No Comments0 Views
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    • Key insight: The attacker picked Revolut’s Lithuanian subsidiary because European law obliges it to answer cross-border evidence demands, targeting the compliance obligation itself rather than working around it.
    • What’s at stake: Every U.S. bank runs a legal and compliance queue that answers subpoenas and government records requests, and it typically sits outside the security team’s view entirely.
    • Expert quote: “Just as we don’t grant someone access to a bank vault simply because they arrived in a marked police car, legal data requests coming through certified channels must undergo zero-trust verification,” said Anu Liinev of Veriff.

    Overview bullets generated by AI with editorial review.

    Processing Content

    Attackers pried hundreds of customers’ passports out of Revolut earlier this year by compromising Italian government email accounts.

    The hackers used stolen credentials to log into real government accounts on a certified email channel built and maintained by the Italian state.

    They emailed phony legal requests over this legitimate channel, so they passed every technical check a bank can run on an email. Revolut answered the requests over several months.

    The London-based fintech confirmed Saturday that an unauthorized third party stole customer records by sending fraudulent information requests from a legitimate government agency’s email domain.

    The attackers told the Financial Times that they posed as Italian law enforcement and said they needed the records for ongoing investigations. The attackers told the news outlet that they used blockchain analysis to pick out Revolut customers with large cryptocurrency holdings.

    Revolut replied with passports and driver’s licenses, the verification selfies customers took to open their accounts, bank account numbers, account statements and full transaction histories, including cryptocurrency activity.

    “Revolut recently identified a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information,” a Revolut spokesperson told American Banker.

    The company blocked the address on detection and alerted the agency, law enforcement, data protection authorities and financial regulators, according to the statement. Revolut has not said how it detected the fraud.

    The incident reached only about 680 customers, none of them in the United States, according to a person close to the company. A group calling itself IAmNotAVillain published a $3 million ransom demand on its own website Wednesday.

    So, the attack was small, but it defeated a process every U.S. bank runs.

    Legal and compliance departments answer subpoenas, court orders and emergency requests for customer records routinely. The safeguards a U.S. banker would use to check that such a request is genuine would not have caught the one Revolut answered.

    It’s not just hypothetical; the FBI warned in 2024 that criminals were sending banks and other companies fraudulent emergency data requests from compromised government email accounts.

    The previous year, Federal prosecutors in Brooklyn charged a man with running that play against American companies. The man took over a Bangladeshi police official’s email account and used it to ask U.S. platforms for their users’ personal details.

    How a stolen password became months of lawful-looking requests

    Someone had stolen credentials for accessing Italy’s government certified-mail accounts before Revolut received any phony government requests.

    Hudson Rock, a cybersecurity intelligence firm, said Tuesday that it reviewed images of the exchange that show the attackers’ correspondence coming from addresses on the Italian Ministry of the Interior’s certified-mail domain.

    Hudson Rock also found roughly 300 compromised logins for that domain already sitting in its own database of stolen credentials.

    That database is built out of infostealer logs; these are programs that infect a computer and copy every password saved in its browser. The files they produce get bought and sold in bulk on criminal markets. Hudson Rock collects them and sells companies access to what it finds.

    The company does not say when the Italian credentials were taken, or whether the attackers used any of the ones it holds.

    It does say it is “highly unlikely” the attackers infected Italian government employees themselves and more likely that they bought logs somebody else had already collected, according to the post.

    A working login is all it takes to send mail through Italy’s Posta Elettronica Certificata system, a state-regulated email service. The Financial Times reported that the requests reached Revolut through that system and that the exchanges ran for months.

    The attackers have also given an account of the campaign to Duel, a group that says it investigates cybercrime and published what the attackers said in a thread on X.

    The hackers told Duel they settled on Revolut Bank UAB, the company’s Lithuanian subsidiary, because it is obliged to answer a European Investigation Order. That is a cross-border demand for evidence that European Union member states can send one another.

    On one occasion, by the same account, the attackers sent a document in the wrong form, and Revolut’s staff explained how to correct it rather than treating it as a reason for suspicion.

    Stolen government mailboxes are already for sale here

    The FBI’s November 2024 notification on fraudulent emergency data requests documented an illicit forum listing “High Quality .gov emails,” including U.S. credentials, and a seller claiming to control government email accounts in more than 25 countries.

    Read more:

    That notification also documented an attempt against a financial services company; a criminal posted photographs on a forum in March 2024 of a fraudulent request sent to PayPal.

    That fraudulent request cited a child-trafficking investigation under a treaty for cross-border evidence and carried a case number and a legal code, according to the notification. PayPal refused the request.

    Because these demands arrive as part of a legal process, they typically go to the lawyers rather than to the security team.

    “At most banks, government data requests land with legal or compliance, not information security,” Denis Calderone, chief technology officer at Suzu Labs, a cybersecurity consultancy, told American Banker.

    “The security team typically has no visibility into what data leaves through that channel because it’s treated as a legal process, not a data transfer,” he said.

    Ownership of that queue “is never standardized across the industry,” said Jason Brown, director of customer advisory and counter fraud lead at the threat-intelligence firm iCOUNTER, who ran one himself as director of risk operations at a payments company.

    The written proof regulators require can also be forged

    The interagency information security guidelines that bind every national bank tell banks to consider controls “to prevent employees from providing customer information to unauthorized individuals who may seek to obtain this information through fraudulent means.”

    The OCC, which gave Revolut conditional approval for a national bank charter earlier this month, said in the charter letter that it requires the new bank to comply with these guidelines (and others) before the agency grants final approval.

    The OCC also told banks a year ago to demand written proof from a government agency before handing over a customer’s financial records.

    A bulletin the office issued in September 2025 says a financial institution “generally may not release a customer’s financial records unless the government authority certifies in writing that it has complied with its obligations under the RFPA.”

    However, that written certification is not a sign that the request is legitimate because an attacker could forge it.

    “A compromised mailbox can forge that certification as easily as it forges the request,” Brown told American Banker. “The document is only as good as the sender behind it.”

    The control that would have caught it

    Whoever sent the request controls the authentication signals, which is why the verification that works has to come from outside the message, according to Brown.

    “A workable independent step verifies the requester, not the request,” he said. “Confirm the named investigator through the agency’s published main line, not a number or address supplied in the correspondence itself.”

    Risk, compliance and legal need to agree on that step in advance, Brown said, “because in the moment, it will feel like friction on a lawful request.”

    Making that call requires something most banks have not built. Calderone called it a verified contact registry of known-good phone numbers and points of contact at the agencies a bank deals with, “independently sourced and never pulled from the incoming request.”

    “A request for basic account records as opposed to a request for passport scans, KYC selfies and full transaction histories are not the same thing and shouldn’t go through the same approval gate,” Calderone said.

    Banks already know how to do this with money. Wire transfers get dual authorization, callback verification and dollar thresholds that trigger escalation, “because everyone understands a wire is sensitive and the loss is immediate,” Calderone said.

    Customer records leaving the building never got that treatment because “a bad payment is the bank’s loss the same day, while released data becomes someone else’s fraud months later somewhere else,” according to Eric Capuano, who runs the security operations center at Black Hills Information Security.

    Certifying delivery “is not the same as identity and authority verification,” said Anu Liinev, fraud optimization manager at the identity verification company Veriff.

    “Just as we don’t grant someone access to a bank vault simply because they arrived in a marked police car, legal data requests coming through certified channels must undergo zero-trust verification,” meaning checks that assume nothing about the sender, she said.

    Calderone’s advice to a bank’s legal intake team was to find the gap in the process for handling legal requests before someone else does.

    “Stress test the procedure by running a tabletop exercise around this exact scenario,” he said. “Walk a fraudulent government data request through your entire intake process and see where it gets caught, or doesn’t.”

    began breach government password Revoluts Stolen
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Admin
    • Website

    Related Posts

    Banks shrug off impact of first rate hike in three years

    September 18, 2026

    Pie or good government? Pay-to-play’s unintended consequences

    September 17, 2026

    What comes next for banks in a post-CLARITY Congress

    September 17, 2026
    Leave A Reply Cancel Reply

    Top Posts

    ‘The Odyssey’ fuels demand for Imax 70 mm screenings

    July 25, 202656

    Vietnam's 10% growth drive runs into economic realities

    July 30, 202616

    Has OpenAI already quietly hit pause on some AI development?

    July 30, 202612

    15 Passive Income Ideas That Actually Work in 2026

    August 13, 202611
    Don't Miss

    With Rates on the Rise, Lean Into the Financials Sector

    By AdminSeptember 19, 20260

    Of all the macroeconomic headlines that occurred this week, none were likely quite as impactful…

    Sandisk Joins the S&P 100 on Monday — the Same Day Nike Leaves It

    September 19, 2026

    5 Things Soaring Diesel Prices Will Make More Expensive

    September 19, 2026

    FTF: Levered Exposure To High Yield Makes It Avoidable, Despite Lower Duration

    September 19, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us

    Welcome to MoneysGuide.com—your trusted source for the latest news, insights, and updates from the world of finance.

    Our mission is to make financial information accessible to everyone. Whether you're an investor, trader, entrepreneur, or simply interested in global markets, we provide timely coverage of the topics that matter most.

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    With Rates on the Rise, Lean Into the Financials Sector

    September 19, 2026

    Sandisk Joins the S&P 100 on Monday — the Same Day Nike Leaves It

    September 19, 2026

    5 Things Soaring Diesel Prices Will Make More Expensive

    September 19, 2026
    Most Popular

    ‘The Odyssey’ fuels demand for Imax 70 mm screenings

    July 25, 202656

    Vietnam's 10% growth drive runs into economic realities

    July 30, 202616

    Has OpenAI already quietly hit pause on some AI development?

    July 30, 202612
    © 2026 MoneysGuide.com. All Rights Reserved.
    • Privacy Policy
    • Terms and Conditions
    • Contact Us
    • About Us

    Type above and press Enter to search. Press Esc to cancel.