Back Teiss Hackers lurked in Revolut systems for five months, demand $3 million ransom
Hackers targeting Revolut demanded a $3 million ransom after siphoning sensitive data by impersonating a government agency via a spoofed email domain.
Last week, Revolut started notifying its customers of a data security incident after the company exposed customer data to a third party following fraudulent requests from a spoofed government email.
According to reports, the confidential information shared with the perpetrators comprised extensive personal and financial data, including names, dates of birth, occupations, residential addresses, email addresses, and phone numbers. The information also reportedly included copies of identity documents, such as passports and driver’s licences, along with facial verification images.
In addition, sensitive financial records—including IBANs, account statements, withdrawal records, and complete transaction histories, including Bitcoin transactions—were reportedly exposed.
A company spokesperson said only a small number of customers were affected. Revolut added that it blocked the email address once the scam was identified, notified the relevant authorities and regulators, and confirmed that its systems and customer funds remain unaffected.
👀 Cinema. Cl0p responded to ShinyHunters and Shiny responded back. Lul "RESPONSE: Its spelt *ShinyHunters, with no space, moron. I told you to bring an English interlocutor. You're a rat. You attempted to intimidate me by saying you'll hand me over to the police. You … pic.twitter.com/sqOViiqqIY — Dark Web Informer (@DarkWebInformer) September 21, 2026
👀 Cinema. Cl0p responded to ShinyHunters and Shiny responded back. Lul "RESPONSE: Its spelt *ShinyHunters, with no space, moron. I told you to bring an English interlocutor. You're a rat. You attempted to intimidate me by saying you'll hand me over to the police. You … pic.twitter.com/sqOViiqqIY — Dark Web Informer (@DarkWebInformer) September 21, 2026
👀 Cinema. Cl0p responded to ShinyHunters and Shiny responded back. Lul "RESPONSE: Its spelt *ShinyHunters, with no space, moron. I told you to bring an English interlocutor. You're a rat. You attempted to intimidate me by saying you'll hand me over to the police. You … pic.twitter.com/sqOViiqqIY
A threat actor using the alias “IAmNotAVillain” has claimed responsibility for the data security incident involving Revolut and listed the company as a victim on the dark web. The actor has reportedly demanded a $3 million ransom and threatened to sell the entire stolen database if the demands are not met.
The fintech giant, howevevr, said it has not not received any “direct or demand from the individuals or group making these claims.”
According to reports publsihed by the cyber threat intelligence and research division of Hudson Rock, Duel investigations team, Revolut responded to the fake government requests for roughly five months through sending fraudulent data requests.
“The hacker gained access to government employee accounts using an infostealer. After gaining entry to an employee’s email, they would log in, add a recovery email under their control, begin logging activities, and silently monitor communications,” researchers noted.
The hackers said it deleted fraudulent emails and monitored the compromised inbox, saving and removing replies as .eml files before the account owner could see them. They initially considered forging court orders but instead targeted Lithuania-based Revolut Bank UAB, which must respond to European Investigation Orders. Over five months, Revolut reportedly processed the hacker’s repeated requests without scrutiny; in one case, support staff allegedly helped correct an incorrect document instead of detecting the fraud.
‼️ BREAKING: We're in with the Revolut hacker. According to them, they didn't only take Revolut data, they've also compromised multiple Italian law enforcement departments. They say the operation targeting Revolut ran for six months, and that they used Italian law… pic.twitter.com/ZYGWZEc0tL — International Cyber Digest (@IntCyberDigest) September 14, 2026
‼️ BREAKING: We're in with the Revolut hacker. According to them, they didn't only take Revolut data, they've also compromised multiple Italian law enforcement departments. They say the operation targeting Revolut ran for six months, and that they used Italian law… pic.twitter.com/ZYGWZEc0tL — International Cyber Digest (@IntCyberDigest) September 14, 2026
‼️ BREAKING: We're in with the Revolut hacker. According to them, they didn't only take Revolut data, they've also compromised multiple Italian law enforcement departments. They say the operation targeting Revolut ran for six months, and that they used Italian law… pic.twitter.com/ZYGWZEc0tL
The hackers now claim to have obtained more than 147GB of data from an Italian law enforcement agency through Revolut, with the matter reportedly under investigation by Italian police.
Please take 30 seconds to register
Already have an account? Sign in
"AI-led spear phishing worries me the most" - Darktrace's Dave Palmer
"Crisis or no crisis; security needs to be the same"
"People need to understand that there isn't an invisible force-field that's protecting them"
"The community needs to recognise and understand crime"
"We've seen a marked increase in social engineering attacks"
"AI-led spear phishing worries me the most" - Darktrace's Dave Palmer
"Crisis or no crisis; security needs to be the same"
"People need to understand that there isn't an invisible force-field that's protecting them"
"The community needs to recognise and understand crime"
"We've seen a marked increase in social engineering attacks"
$12M Vanishes in Crypto Heist Targeting Cork Protocol’s Depeg Market
$600 million stolen & returned in biggest ever crypto heist
10-month cyber attack exposes personal data of South Korean diplomats
Closing the exposure window — unifying continuous threat exposure management
Trusting your AI agents
The blind spots in your stack - why fragmented data security fails
Winston House, 3rd Floor, Units 306-309, 2-4 Dollis park, London, N3 1HF
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
