The Attackers Never Touched Revolut's Systems. They Just Asked Nicely. For Five Months.

What would your team do if a request for customer records arrived from a real government email address?

If the answer is "fulfill it," you now have something in common with Revolut.

What Happened

On September 12th, Revolut confirmed it had handed customer files to someone who was not a government official. The request came from a legitimate government agency's email domain. Not a spoof or a lookalike address registered in another country. A real domain, used by the wrong people.

The exposed data included know-your-customer (KYC) material. This means that it had identity documents customers submitted at signup, whether that is a passport or driver's license, plus selfies and transaction histories.

Around 680 customers across several European countries were affected. The Financial Times reported that the attackers claim they compromised an Italian government email system and spent roughly five months corresponding with the bank while posing as law enforcement.

Now the group is demanding 6,000 XMR, which is the cryptocurrency Monero. As of September 17th, this is the equivalent of $2.9 million, and they are threatening to publish more customer data if Revolut doesn't pay.

The Alarming Part

Nobody broke into Revolut. The attackers didn't defeat a single one of Revolut's security controls. They used them. Revolut's team did exactly what a well-run compliance operation does: it responded to an official request that arrived through an official channel. The channel was compromised. The company wasn't.

Researchers at Duel and Hudson Rock traced the initial access to infostealer malware, the same category of password-stealing software that infects computers through reused credentials and malicious links every day. Once inside the government mailbox, the attacker reportedly added a recovery address and quietly monitored communications for months.

And the extortion site? KELA's investigators found it was assembled in about six and a half hours on free public hosting, with a public repository and commit metadata. This wasn't a nation-state operation or a zero-day exploit. It was a criminal with a stolen mailbox and patience.

A trusted channel, along with a patient liar, is what got a company with one of the most sophisticated fraud and security teams in fintech to package up its own customers' identity documents and ship them out.

Why This Maps Directly to You

We spend our days inside credit unions, banks, construction firms, manufacturers, and nonprofits, and every one of them has a version of this workflow.

If you run a credit union, your team receives legal process and law enforcement requests on a regular basis. A subpoena shows up, someone verifies it looks right, and records go out the door. If you run an AEC firm, it's agency correspondence, permitting offices, and procurement emails. If you run a nonprofit, it's grant agencies and institutions asking for documentation on your donors and programs.

The details change, but the pattern doesn't. Every organization has channels it treats as inherently trustworthy, because the requests that come through them are routine and verifying them is slow.

The Revolut incident is what happens when that assumption quietly stops being true, and nobody notices for five months. 

There's a second layer here that we talk about constantly with clients. The infostealer problem isn't yours until it is. The Italian government mailbox was taken over the same way small businesses get taken over every week, with an infected machine, a stolen session, and a recovery address added before anyone noticed. The attacker didn't need to compromise Revolut or the government. They just needed one unremarkable computer somewhere in the chain between them.

What to Do with This

Treat inbound authority requests as unverified until proven otherwise. The fix isn't suspicion of everyone. It's a callback. Verify the request out of band. Call the agency back using the phone number from its official website and never use the one in the email signature. If the request is real, a legitimate agency will not object to a verification call. That single habit breaks this entire class of attack.

Slow the workflow down on purpose. A 30-minute delay in fulfilling an information request costs nothing. A five-month silent disclosure of KYC documents costs everything. Build the pause into the process, so it doesn't depend on an individual employee choosing to be careful on a busy Tuesday.

Check whether your credentials are already in criminal hands. Infostealer logs are traded in bulk, and most organizations have no idea how many of their employees' sessions are sitting in those dumps. This is a concrete, finite exercise, and it's usually the fastest way to find out if someone is already positioned inside a mailbox you trust.

Run this exact scenario in your next tabletop exercise. We keep recommending tabletops because they keep working. Make the scenario specific: a records request arrives from a real regulator's domain, and the "regulator" follows up twice to ask why it hasn't been fulfilled yet. Watch what your team does. Most teams hand over the records within ten minutes, and watching that happen in a conference room is worth a year of awareness posters.

To Sum It Up

The most dangerous email your organization receives this year won't look dangerous. It will look like a procedure.

Revolut will probably weather this. They have the resources, and their systems and customer funds were reportedly untouched. But you don't need to be a global fintech to be in this story. You just need a team that answers official-looking requests from official-looking places, which is every team we know, including the good ones.

If you want help pressure-testing your request-handling workflow or finding out whether your organization's credentials are already circulating in infostealer logs, that's a conversation we're happy to have. Contact us today.

Contact the Experts