Tech News

Revolut Data Leak: Hacker Claims Italian Police Breach and 147 GB of Data

Six months of intrusion, 147 GB of data, and Italian police services allegedly used as the entry point: that is what the hacker behind the Revolut data leak claims. These statements should be taken with caution, but they give this case a whole new dimension. Here is what we know.

Yesterday morning, I published an article about the Revolut data leak, in which the neobank handed over passports, selfies, and transaction histories to a hacker who spoofed the email domain of a government agency. As a reminder, Revolut acknowledged on September 12, 2026 that it had responded to fake information requests sent from the genuine email domain of a public administration. The company never named that administration and referred to a very limited number of affected customers, without giving a figure.

Since then, the case has taken on an almost familiar twist: extortion. But now it is also clear that this incident goes far beyond Revolut. The reason is that the alleged attackers have begun publishing data on Telegram. And according to The Register, the data excerpts posted involve business executives, professional athletes, and artists. Meanwhile, the hacker using the alias IAmNotAVillain is demanding 10,000 bitcoins, which amounts to about €673 million according to Revolut’s own converter.

Most notably, to put pressure on Revolut, they are threatening to publish "more and more data every day until Revolut pays for leaking its customers". Among the people named in those posts are tennis player Alexander Shevchenko and Felix Römer, a director at the crypto casino Gamdom. There is also reportedly Georges Mikautadze, the professional footballer currently at Villareal in Spain. In fact, the hacker is mistaken, as he presents him as a FC Barcelona player, a rumor that never materialized into a transfer.

Source: X.com

Most importantly, France and Switzerland would be the two countries most affected by this Revolut data leak, even though around thirty countries are reportedly involved in total. The fact that this may have been a targeted operation (wealthy customers) but geographically broad is not contradictory.

Were Italian police services used as the entry point?

Screenshots shared on Telegram by the hacker’s account suggest that the emails sent to Revolut came from an Italian domain. According to the account International Cyber Digest on X, the hacker IAmNotAVillain may have compromised Italian law enforcement systems to send the data requests.

"URGENT: We are in contact with the Revolut hacker. According to them, they did not just take data from Revolut, they also compromised several departments of the Italian police. They say the operation against Revolut lasted six months, and that they used Italian police systems to send data requests to Revolut.", it reads.

That is not all. The hacker also claims to possess 147 GB of data from several Italian police services, including internal documents, calendars, and personal material, such as conversations from an officer arguing with his wife. A supporting screenshot shows a folder named Italy, sized at 147 GB, containing 36,393 files spread across 5,223 folders.

If all of this is confirmed, the case would take on an entirely different dimension... But for now, although it appears credible, neither Revolut nor the Italian authorities have responded to these claims.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.