September 25, 2026
at
4:40 am
EST
MIN READ
.jpeg)
A few weeks ago, Revolut acknowledged for the first time that it had suffered from a significant data breach that occurred over a several months long period earlier this year.
The hacker, who goes by the name iamnotavillain, initiated the breach by compromising an Italian government email system and then posing as an Italian law enforcement agency to contact Revolut and ask for sensitive information. Earlier this year, Revolut was fined $13.25 million by Italy’s competition authority which may have made them more susceptible to the hack.
Posing as the agency, the hacker then proceeded to request the full KYC information of 680 Revolut account holders. Revolut complied with the requests, resulting in a significant data breach.
The account holders were reportedly all from Europe, with the majority being from France and Switzerland. They were also all high net worth crypto whale accounts. Since then, the hacker has leaked KYC information for some of these account holders, in an attempt to get Revolut to pay a $3 million ransom.
The hacker said this to the FT regarding how the accounts were identified:
“I rather not disclose my exact way of getting it, but it was via onchain analysis.”
Read our comprehensive guide to on-chain analysis here.
While the hacker refused to reveal their exact method, the public nature of blockchains offers some clues as to how the 680 victims were selected.
As a CEX, Revolut operates its own crypto addresses and on-chain wallets which are publicly visible. On public blockchains, flows of funds in and out of addresses can be observed by anyone. With this information, the hacker would be able to identify crypto whales who have Revolut accounts.
Revolut is a labelled entity on Arkham, you can interact with the Revolut entity in the window below:
However, on-chain data alone cannot reveal a wallet owner's identity. Blockchains record addresses, not names. To obtain the personal information behind the accounts, the hacker relied on social engineering - posing as Italian law enforcement to trick Revolut into handing the KYC data over.
In this instance of a data breach, blockchain security is not the issue. Public blockchains are transparent by nature and the crypto whales in question knew this. The weak point in the chain was the off-chain identity data held by platforms. In this case, Revolut's systems were never breached - the data was requested, and handed over after a sophisticated social engineering scam.
.jpeg)
.jpeg)














.png)
.png)






























.jpg)
.jpg)


















.png)
.png)
.png)
.png)










.png)
.png)




.png)
.png)


.png)
.png)


.png)
.png)


.png)
.png)
.png)
.png)


















.png)
.png)


.png)
.png)
.png)
.png)


.png)
.png)








.png)
.png)







