Revolut Leak: Hacker Claims Italian Police Breach and 147 GB of Data
Six months of intrusion, 147 GB of data, and Italian police services used as an entry point: that is what the hacker behind the Revolut data leak claims. These statements should be taken with caution, but they give this case a whole new dimension. Here is what we know.
Yesterday morning, I published an article about the Revolut data leak, in which the neobank handed over passports, selfies, and transaction histories to a hacker who spoofed the email domain of a government agency. For the record, Revolut admitted on September 12, 2026, that it had responded to fake information requests sent from the authentic email domain of a public administration. The company never named that administration and referred to a very limited number of affected customers, without providing a figure.
Since then, the case has taken a nearly predictable turn toward extortion, but it is now also clear that this incident goes far beyond Revolut. The reason: the alleged attackers have begun publishing data on Telegram. And according to The Register, the data samples posted concern business leaders, professional athletes, and artists. For their part, the hacker known as IAmNotAVillain is demanding 10,000 bitcoins, which is roughly 673 million euros according to Revolut’s own converter.

More importantly, to pressure Revolut, they are threatening to publish "more and more data every day until Revolut pays for exposing its customers". Among the people named in these posts are tennis player Alexander Shevchenko and Felix Römer, the CEO of crypto casino Gamdom. Georges Mikautadze, the professional footballer currently at Villarreal in Spain, is also said to be among them. Incidentally, the hacker is mistaken here, as he identifies him as a FC Barcelona player (a rumor that never resulted in a transfer).

Most importantly, France and Switzerland would be the two countries most affected by this Revolut data leak, although around thirty countries are involved in total. The fact that this may have been a targeted operation (wealthy customers) but geographically broad is not contradictory.
Italian police services as the entry point?
Screenshots shared on Telegram by the hacker’s account suggest that the emails sent to Revolut came from an Italian domain. According to the account International Cyber Digest on X, the hacker IAmNotAVillain may have compromised Italian law enforcement systems to send the data requests.
"URGENT: We are in contact with the Revolut hacker. According to them, they did not just take Revolut data, they also compromised several departments of the Italian police. They say the Revolut operation lasted six months, and that they used the Italian police systems to send data requests to Revolut.", it reads.
That is not all. The hacker also claims to hold 147 GB of data from several Italian police services, including internal documents, calendars, and personal items, such as conversations between an officer and his wife during an argument. A supporting screenshot shows a folder named Italy, sized at 147 GB, containing 36,393 files spread across 5,223 folders.
If all of this is confirmed, the case would take on a whole new dimension... But for now, although it appears credible, neither Revolut nor the Italian authorities have responded to these claims.


