How Could the Revolut Data Breach Have Been Avoided? A Financial Crime Expert Weighs In

Hackers who call themselves "ImNotAVillain" have claimed responsibility for the Revolut customer data breach. Photo: Unsplash / appshunter.io
The data breach involving hundreds of customers of the neobank Revolut should be viewed as a combination of a cyberattack and a failure in the bank’s internal procedures, according to Marco Beranzoni, a financial crime prevention specialist and founder of the FinCrime Agent platform. He has nearly 20 years of experience in cybersecurity, having held positions at some of the world’s largest financial institutions, including HSBC, Standard Chartered, and Bank of America Merrill Lynch.
While the attackers may have compromised or exploited Italy's government communications infrastructure, the very fact that customer data was transmitted to the fraudsters points to weaknesses in the procedures for reviewing and approving high-risk requests, Beranzoni explained in a comment to Oninvest.
“This is a sophisticated impersonation attack, but it doesn’t necessarily involve a technically complex breach of Revolut’s systems,” he says. Even if a request comes from a compromised but seemingly legitimate government email address, it can pass standard technical email authentication and appear convincing to a bank employee, the expert notes.
In his view, the main question now is whether Revolut conducted—and, if so, how—an independent review of the request from alleged government agencies before handing over the data of certain customers.
Beranzoni adds that if a request is urgent, it can create a particular vulnerability, since the urgency is used as a justification for bypassing standard legal procedures. “Banks and fintech companies must independently verify the organization, the employee, and the request itself through a trusted channel that is not specified in the request itself. Calling the phone number listed in the same email or document is not enough,” the expert emphasizes.
The disclosure of confidential information should also require verification by a second employee, even if the request appears to be urgent, the financial expert adds.
He also expresses concern that attackers obtained data on customers with significant cryptocurrency holdings and identified those customers through blockchain analysis.
“Public blockchain data can help criminals identify valuable crypto wallets, while leaked information can link these wallets to real people, their addresses, and identification documents. Even if no funds were directly stolen as a result of this incident, affected customers may face targeted phishing, account takeover attempts, extortion, or potential risks to their physical safety,” warns Beranzoni.
What Is Known About the Attack on Revolut
Revolut first reported the incident on September 11. Hackers who call themselves “ImNotAVillain” claimed responsibility for the leak of Revolut customer data. According to the Financial Times, they hacked into an Italian government email system and spent several months posing as law enforcement officials. This allowed them to obtain confidential information about the neobank’s customers. The attackers gained access to information on approximately 680 customers.
The IAmNotAVillain group later demanded a $3 million ransom from Revolut for customer data, threatening to sell the information.
"Revolut has not received any direct contact or demands from individuals or a group claiming responsibility for this attack," a Revolut spokesperson said in a statement to Oninvest.
Context
The incident involving the transfer of customer data by the neobank comes amid Revolut’s large-scale international expansion. In 2026 alone, the fintech company obtained a full banking license in the United Kingdom, followed by one in France in August, and in early September received conditional approval for a license in the United States; it continues to expand its presence in other jurisdictions.
At the same time, the neobank is preparing for a potential public market debut. According to the company’s founder, Nick Storonsky, the IPO could take place no earlier than 2028. According to the Financial Times, the bank’s goal is to become a global player by that time, with a valuation of up to $200 billion. As Oninvest reported, citing expert estimates, Revolut’s ambition does not seem unattainable given the current growth in revenue, profits, and customer base.
This article was AI-translated and verified by a human editor




