“The Blood Will Be On Your Hands,” Revolut Hackers Warn

“The Blood Will Be On Your Hands,” Revolut Hackers Warn

Hey all, Jason here.

While I’ve intentionally dialed back my speaking-and-travel schedule this year, I will be at several events in the coming months.

I’m looking forward to speaking at Momentum by Monato in Mexico City on October 13th. If you’re in CDMX or want to attend, you can register here and get a 10% discount with code JASON.

I’ll be in Mexico City for a few additional days before heading to Las Vegas for Money20/20, so if you’re based there and are interested in catch up, feel free to let me know by replying to this email or messaging me elsewhere.

I’ll also be in Washington, D.C., in November to speak at the American Fintech Council Policy Summit. More info on that here.

Looking forward to catching up with industry friends and colleagues in person this fall!

Subscribe or Support by Upgrading

Partner content: A customer signs up for your platform. They get their own account and routing number. They receive an ACH payment and see the right balance in your product.

To them, it’s simple. Behind the experience, your platform has two jobs:

  1. Move the money correctly

  2. Maintain an accurate record of what happened

Modern Treasury brings both together.

Offer your customers more ways to pay and get paid with ACH, wires, RTP, FedNow, push-to-card, checks and stablecoins.

And easily segregate funds with sub-accounts and ledger every transaction to the right balance.

Everything works together from day one, so your team can focus on your roadmap.

Trusted by Procore, Navan, and companies of all sizes. Powering $600B+ in payments.

See What You Can Build

Notice of Proposed Rulemaking: State Bank Parity (FDIC)

Initial Findings from Independent Review of Silicon Valley Bank (Fed Vice Chair for Supervision Michelle Bowman)

SEC Issues “Innovation Exemption” to Facilitate the Trading of Tokenized NMS Stock and Request for Comment (SEC)

Consumer & Community Context: What is Buy Now, Pay Later? (Federal Reserve)

Artificial Intelligence Supervisory Framework (Conference of State Bank Supervisors)

Raiffeisen Bank International-Linked Customs Records Show $1.19 Billion in Trade Matching Sanctions and Export-Control Restrictions (Grizzly Research Short Seller Report)

How Fintech Onboarding Really Works (Fintech Under the Hood)

Winding Down Banks’ Free Money Machine (Fintech Takes Banking)

Listen: Inside Treasury’s Push to Reset Bank Regulation (Banking With Interest)

Pay-by-bank startup Trustly has laid off about 24% of staff, 205 roles, according to an internal email announcing the move exclusively obtained by Fintech Business Weekly.

Trustly’s U.S. clients include Coinbase, T-Mobile, MoneyGram, Dell, FanDuel, DraftKings, and Western Union, among others.

The company informed employees last week, with Trustly CEO Johan Tjärnberg writing in an email to employees, “We are not meeting the opportunity in front of us with the level of execution it demands. The way we are set up has made it harder than it should be to deliver: structures have become too complex, work is duplicated, ownership is unclear, and investment is not aligned with our priorities.”

While Trustly has grown revenue by loosening risk controls in order to increase approval rates in the U.S., adjusted EBITDA has shrunk as losses have grown, a Q2 presentation to bondholders shows.

graphical user interface, application

Trustly reported adjusted EBITDA of SEK 42 million in Q2 (about USD $4.3 million), a sharp decrease from SEK 85 million ($8.65 million) in Q2 2025. The company had negative SEK 261.7 million ($26.6 million) cashflow for the first half of 2026. “Management are very focused on liquidity, with multiple levers available,” the Q2 2026 bondholder presentation said.

The layoffs primarily impacted the Brazil operations, with all or nearly all of that team terminated.

Key legal and compliance staff in the U.S. were also impacted, sources with knowledge of the matter told me. Trustly operates in the U.S. via money transmitter licenses; a review of NMLS shows it holds such licenses in at least 41 jurisdictions. An impacted employee in Canada described the Canadian branch of Trustly as having been “dissolved.”

A Trustly spokesperson confirmed the layoffs, saying, “We’ve shared proposed organizational changes with our employees that impact around 200 roles globally. These changes are about sharpening our focus and concentrating investment behind the priorities that will help us lead the rapidly growing open banking market. We understand the impact this will have on those whose roles are affected, and we’re supporting every employee throughout the process.”

Partner content: Bretton AI is offering a three-part series for banking and fintech teams who want to explore AI beyond Copilot and chatGPT and apply it to actually transform their businesses.

Every bank has been told AI changes everything. Most have a pilot, a committee, and a vendor list, but very few have something in production with proven ROI and appeases your regulator.

This series seeks to help you do just that. Over three hours across three weeks, the Bretton AI team, including two AI engineers, will walk through what the technology is actually capable of. We’ll explore where it falters, what controls it needs to survive an exam, and how to get from a promising demo to a system your institution depends on. This won’t be a product pitch; this will be composed of the same material we walk our own bank customers through before go-live.

Bretton AI runs production AI inside regulated banks and fintechs every day. Learn about how it’s actually done.

Save Your Seat

What may have at first seemed like yet another data breach ricocheted across the internet and Europe last week, with a group operating under the name IAmNotAVillain threatening to sell identity information and account balances and transaction histories, including crypto, of about 680 Revolut users.

The users whose data were compromised appear to have been targeted because they are crypto “whales,” an industry term used for those who own significant amounts of cryptocurrencies. People known to hold large amounts of crypto have increasingly become targets of kidnapping, extortion, and other threats, owing at least in part to the perceived ease of stealing, moving, and laundering crypto vs. traditional bank deposits or other assets.

Users with information compromised in the breach appear to include Mark Karpelès, the former CEO of Mt. Gox, once the world’s largest bitcoin exchange before collapsing following a hack and theft of some 850,000 bitcoins; Felix Romer, founder of online casino and sportsbook Gamdom; Alexander Shevchenko, a professional tennis player; and Georges Mikautadze, a professional football (soccer) player, among others.

The person or group demanded a ransom of 6,000 XMR, a decentralized, privacy-focused cryptocurrency; 6,000 XMR equates to approximately $3,000,000.

On Wednesday, September 16th, the hacker demanded 6,000 XMR / $3,000,000 within 24 hours, threatening to begin selling Revolut users’ data if the demand was not met.

IAmNotAVillain said that, if the ransom demand was not met, they would sell the data — potentially compromising the physical safety of the users — and warned “the blood will be on your hands.”

While IAmNotAVillain’s underlying operation to exfiltrate the data from Revolut appears to have been in progress for around six months, information about the incident started to spread following an email Revolut sent to impacted users on or around Friday, September 11. Some of the victims commented on social media that they had been the subject of extortion attempts in recent months, though it is unclear if those attempts were linked to the compromised Revolut user data.

In copies of the email shared by impacted users Revolut stated (emphasis added):

“We’re reaching out to inform you of a recent security incident involving an external impersonation scam that resulted in some of your personal data being shared with an unauthorised third party…

“Revolut received a request for customer information that appeared to come from a legitimate government agency. The request came from an unauthorised email account sent directly using the official government agency’s email domain.

“As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request.

“As soon as we detected potential risk factors, we alerted the relevant authority about the compromise within its domain. We immediately blocked the address across all systems.”

According to the communication to impacted users, compromised information included:

  • Identity details: full name, date of birth, occupation

  • Contact details: postal address, email address, phone number

  • Document and verification data: copy of identity document (eg drivers license/passport/residence permit), and facial verification image (“selfie”)

  • Financial account data: account statements (including IBAN, account status, opening date, wallet reference number), withdrawal records, and full transaction history (including bitcoin)

Following Revolut’s detection of the leak and email to impacted users, IAmNotAVillain, the threat actor, began releasing information purportedly obtained through the hack on messaging app Telegram and on the web.

The hacker began releasing documents purportedly obtained in the hack and communication with Revolut, ostensibly to prove the documents’ authenticity.

Over the course of last week, successive Telegram channels and websites that appeared to be operated by IAmNotAVillain popped up but eventually were blocked or deactivated, apparently for terms of service violations.

As of the time of publication, none of the previously used sites or Telegram channels appear to be operational.

Additional messages sent directly to IAmNotAVillain via secure messaging app Session, where Fintech Business Weekly had previously been corresponding with the apparent threat actor in an attempt to confirm various details of the incident, did not receive a response.

Documents, screen captures, and a video shared by the hacker appear to indicate that they exploited an official Italian government email system to send forged legal requests to Revolut requesting users’ data.

The system, La Posta Elettronica Certificata (abbreviated PEC), is a secure email network overseen by the Italian government and used by government agencies, companies, and individuals to exchange official or legal correspondence. It is roughly the electronic equivalent of registered/certified mail.

The domain visible in numerous images, pec.interno.it, belongs to the Italian Ministry of the Interior.

An additional image circulating, which Fintech Business Weekly has not independently verified, show the originating address as [email protected] — belonging to the Prefecture of Reggio Calabria, a locality at the very southern tip of Italy.

The alleged illicit use of this Interior Ministry address has been widely reported, including in the Financial Times and Italian press. The public prosecutors office in Reggio Calabria has reportedly opened an investigation into the matter.

It appears an “infostealer” installed on a compromised computer in that government office compromised the login information for this official government mailbox.

An email that appears to be from Revolut to the hacker providing documentation on some users, while specifying certain hashes (wallet addresses) are associated with users in the U.K. or Switzerland, where the legal instrument used wouldn’t authorize Revolut to release the requested information.

Other outlets have reported that, given the shared nature of the general purpose email address, the hacker would delete outbound emails they had sent and would monitor for inbound replies, downloading any responses and attachments and deleting them to avoid detection.

The hacker told the FT that they used blockchain analytics to identify Revolut users with significant crypto holdings, writing, “I rather not disclose my exact way of getting it, but it was via onchain analysis.”

While techniques vary by chain, approaches like clustering addresses based on a known wallet and tracking payments of “gas” fees can be used to link specific wallet addresses with centralized exchanges like Revolut.

The hacker appears to have then used forged European Investigation Orders, sent from the compromised Italian Ministry of the Interior email address, to request account and transaction information associated with the specified wallet addresses.

Image
A purported image of a forged European Investigation Order used by the hacker. Fintech Business Weekly has not been able to independently verify the authenticity of this image (that this was actually used by the hacker).

Based on images of the emails purportedly shared by the hacker, it appears that Revolut declined to share information for some accounts, depending on the geographic location of the legal entities and/or end users with which they were affiliated, but did share data on approximately 680 accounts.

The threat actor also publicly shared purported communication from Revolut requesting the deletion of previously sent documentation for at least four Swiss-based nationals.

The email that appears to be from Revolut (image below, top left corner), presumably to the compromised Italian ministry address, says that “the aforementioned accounts are subject to a different jurisdiction and, since the information is bound by the requirements of banking secrecy, we should not have provided any information. If deemed necessary, we invite you to consider the issuance of a formal request by a Lithuanian or Swiss authority.”

The hacker claims that Revolut released information for users in jurisdictions that it should not have and subsequently requested it be deleted.

The framework for issuing and fulfilling a European Investigation Order is defined by Directive 2014/41/EU, as amended by Directive 2022/228.

Per this framework, such orders can be issued by a judge, court, investigating judge, or public prosecutor competent in the case.

In the EIO shown above, which has not been independently verified as what was sent to Revolut, the authority specified is the “Public Prosecutor’s Office at the Court of Milan” — even though the email account it appears to have been sent from is associated with the Italian Ministry of the Interior, and specifically the locality of Reggio Calabria, more than 1,200 kilometers from Milan.

The legal framework for such requests describes transmitting an EIO from an issuing authority — the Public Prosecutor’s Office at the Court of Milan, in the case of the apparently forged document shown above — to an executing authority in the target country.

An “executing authority” would be a state actor defined by relevant national law, not Revolut itself. In the case of Lithuania, where Revolut’s bank entity is based, it appears the proper executing authority for an EIO related to a pre-trial investigation would be Prosecutor General’s Office and/or the relevant Regional Prosecutor’s Office.

The image of the EIO that the hacker purportedly sent to Revolut does specify the “General Prosector’s Office of Lithuania” as the executing authority, but it appears this document was sent directly to Revolut, which is not how the process is designed to work.

Per Article 5 of Directive 2014/41/EU, an EIO shall contain:

  • data about the issuing authority and, where applicable, the validating authority;

  • the object of and reasons for the EIO;

  • the necessary information available on the person(s) concerned;

  • a description of the criminal act, which is the subject of the investigation or proceedings, and the applicable provisions of the criminal law of the issuing State;

  • a description of the investigative measures(s) requested and the evidence to be obtained.

Further, per Article 26 part 5, which governs requests on bank and other financial accounts, an EIO shall “indicate the reasons why it considers that the requested information is likely to be of substantial value for the purpose of the criminal proceedings concerned and on what grounds it presumes that banks in the executing State hold the account and, to the extent available, which banks may be involved.”

Finally, the image of the EIO that was purportedly used (above left) by the hacker does not align with the European Judicial Network template for such requests (above center), nor the Italian language version of that same template (above right) available on the Italian government’s website.

There has been some additional reporting suggesting the hacker may have used a more recently enacted legal instrument, known as a European Production Order, which can be sent directly to the entity being asked to produce the data, rather than to an executing authority in the target’s jurisdiction. However, Regulation (EU) 2023/1543, which creates the instrument, appears to have only come into force as of August 18, 2026, and specifically excludes financial services from its scope.

Revolut did not respond to multiple emails with questions and request for comment, including regarding what policies and procedures the company has in place for handling requests from law enforcement and whether or not they were followed in this case.

The 24 hour deadline IAmNotAVillain gave for Revolut to pay the ransom came and went, and, as of yet, there is no indication the hacker has begun selling the data.

The various sites and Telegram channels the hacker had used to publicize the breach have all been taken down, and IAmNotAVillain, who had previously responded to messages from Fintech Business Weekly via messaging app Session, did not respond to multiple follow up inquiries.

Information security professionals Fintech Business Weekly spoke to speculated that the person or group behind the hack are not professional, organized cybercriminals and may be struggling to monetize the data they appear to have obtained.

While there is, as of yet, no indication firms other than Revolut have had data obtained in a similar manner, given the nature of the compromise, it is entirely possible the hacker used the same approach to attempt to obtain data from other financial institutions.

The incident comes at a sensitive time for Revolut, as the company works to operationalize its U.S. bank charter, for which it received conditional approval from the Office of the Comptroller of the Currency earlier this month.

One of the requirements before Revolut can gain final OCC approval is that it “must have a security program in place that complies with the ‘Interagency Guidelines Establishing Standards for Safeguarding Customer Information’ specified at 12 CFR 30, Appendix B.”

The company is also plotting an IPO. Revolut cofounder and CEO, Nik Storonsky, said just last week — in the midst of the data breach fallout — that the company is exploring a dual listing in New York and London, though he has previously said and such public offering wouldn’t take place until at least 2028. Revolut was recently valued at $115 billion in a private secondary market transaction.

High-APR lender Enova International has abandoned its $369 million acquisition of Grasshopper Bank, citing regulatory uncertainty and “political pressure and outside advocacy.” Meanwhile, the OCC, FDIC, and Federal Reserve released a statement earlier this month that is functionally a warning to the big three core banking providers, FIS, Fiserv, and Jack Henry.

More on both of these after the paywall.



Source link

Leave a Reply