Revolut, a prominent British fintech company, is grappling with a serious data breach that lasted for five months. Hackers managed to extract sensitive information by posing as a legitimate government agency. In response to what it believed were authentic requests from law enforcement, Revolut unknowingly handed over personal data belonging to 680 high-profile customers. This information included personal details such as email addresses, phone numbers, and financial data. The hackers, identifying themselves as 'IAmNotAVillain', have demanded a ransom of $3 million and threatened to sell the compromised data.

The breach was facilitated through the compromise of a government employee's email account, which was then used to send fraudulent requests to Revolut's Lithuanian subsidiary, Revolut Bank UAB. The hackers claim they have also acquired over 147GB of data from an Italian law enforcement agency. Despite these claims, Revolut has stated that it has not been contacted directly by the attackers.

The cybersecurity firm Hudson Rock has indicated that the breach was likely made possible by accessing pre-existing stolen credentials rather than directly infecting the employee's systems. The Italian police have initiated an investigation, and Revolut is working to address the situation while notifying affected users. This incident underscores the importance of verifying the legitimacy of legal requests to prevent unauthorized data access.