On Monday, 14 September 2026, the UK based financial institution Revolut confirmed they had disclosed sensitive customer information to an unauthorized third party. Quickly information and samples of this data began to circulate on the darkweb. In this blog we explore what happened.

Revolut is a British financial technology company and digital banking platform headquartered in London, England.
The company was founded in July 2015 by Nikolay (Nik) Storonsky and Vlad Yatsenko. They offer digital banking services, international money transfers, multi-currency accounts, budgeting tools, stock trading, and cryptocurrency exchange through a mobile app.
In the UK they operate as a fully licensed bank, authorized by the Prudential Regulation Authority and the Financial Conduct Authority, as well as across the European Economic Area, alongside partner-backed financial services globally.
Revolut has experienced exponential growth since its inception in 2015, transforming from a simple digital travel-card app into Europe’s largest digital bank.
Revolut confirmed it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain.
The data exposed reportedly contained customer identity information, contact details, DOB (date of birth), addresses, email addresses and phone numbers. As well as images that are routinely used by organizations to prove KYC (Know Your Customer), which often include a selfie, identity documents and proof of date, as well as identity documents such as passports and driver’s licenses.
A Revolut spokesperson confirmed a “limited” number of customers were impacted and they had been contacted directly. Further reporting suggests approximately 700 customers were affected, with the highest profiles and affluent being targeted.
According to reporting from TechCrunch, who spoke with a Revolut representative, “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.”
A cyber security researcher stated that they had been in touch with the Revolut hacker and they claimed they had also compromised multiple Italian law enforcement departments and that access is what they used to send data requests to Revolut.
Once the intrusion was announced, the Darkweb, and particularly Telegram, chatter began about who was responsible for this. Actors claiming responsibility began to emerge.
On 13 September a Telegram channel was created which claimed to share images and data linked to the breach of Revolut. The channel claimed to have data from Kraken and Poloniex as well as naming specific individuals and their personal information.

The channel went on to share downloads linked to the companies mentioned.

The channel also shared documents directly which appeared to be invoices or internal documents from Revolut. The actor watermarked the documents with their Session ID and Telegram account.

The account also shared further information in case the channel was banned by Telegram, this included details of their Session ID and their personal Telegram handle.
The website provided information about the hack and the reasons for leaking the information which was cited as the company closing accounts for no reason and freezing funds. The website was hosted on the clear web. By 15 September, it appeared to have been taken down. A message posted on the Telegram channel indicated that the threat actor may have deleted the page.

The site also included an AI chatbot which you could use to message the threat actor directly regarding the leak.

On September 14, the Telegram channel shared an image of a message from Telegram relating to one of the backup channels that has been created stating that several companies had made a complaint against the channel as it infringed on their copyright. The message stated the owner of the channel should contact the copyright holder direct to resolve the issue. The validity of this message has not been confirmed.

The actor posted on their Telegram channel that they were open to being interviewed by journalists free of charge.
It was then identified that a second website had been created, as well as a new Telegram channel also claiming to be the threat actor behind the attack. This threat actor had been in contact with journalists. The handle used by this threat actor is IAmNotAVillain.
The website created used different colors to the previous website and a different name, however, does have similar sections explaining the leak. The session ID provided and the Telegram channel are also different from the first actor. This site claims an individual who was working with them, took a small sample of the data and is using that to claim they are behind the attack. They warn this is a scam.

On the site the actors began to release images to prove they had access to the data, showing KYC selfies and identity documents as well as account information including financial data.


On the Telegram channel the group state that they have not yet announced a price they want for the data:

They also state more data is coming:

As well as sharing more samples through file sharing sites.
This is a developing incident. DarkOwl Analysts will continue to monitor.
Products
Services
Use Cases