Around 680 Revolut customers were reportedly affected, including professional athletes whose personal and financial information may have been exposed.
Tennis player Alexander Shevchenko and footballer Georges Mikautadze have reportedly been caught up in Revolut’s customer data leak.
A group calling itself IAmNotAVillain has claimed responsibility for the incident and launched a website where information belonging to Revolut customers has been published.

Shevchenko and the Villarreal forward have both been reported as having data exposed, which includes passports, driving licences, photographs, home addresses, IBANs, account statements and full transaction histories.
Shevchenko has competed on the ATP Tour since breaking into the world’s top 100 in 2023 and reached a career-high singles ranking of No.45 in February 2024. The 25-year-old represents Kazakhstan internationally.
Mikautadze is a Georgia international who joined Villarreal after spells with Metz, Ajax and Lyon. The forward finished his first season with the Spanish club as its top La Liga scorer with 13 goals.

Revolut notified 680 customers following the incident, a small proportion of its more than 80 million customers worldwide.
Gamdom CEO Felix Römer, who’s confirmed he was affected by the leak, said on X that some customers had already faced attempts to exploit the stolen information before Revolut publicly confirmed the breach.
“Already 2 months ago me and others started to get blackmailed with the compromised data,” he wrote.
How did the Revolut leak happen?
Revolut confirmed the breach on 12 September after an unauthorised third party submitted fraudulent information requests through a legitimate government agency email domain.
The requests appeared genuine and customer information was released before Revolut discovered the person making them wasn’t authorised.
Revolut has described the incident as an “external impersonation scam” and stressed that its own systems weren’t breached and customer funds remained safe. The company blocked the email address and contacted the government agency, law enforcement and relevant regulators.
Reports suggest that IAmNotAVillain claims it compromised Italian law enforcement systems and used them to make requests to Revolut over a period of around six months.
The group also claims to hold 147GB of information from the Italian department, including internal documents and communications. The claims haven’t been independently verified.
What’s at risk for affected athletes?
For those affected by the leak, passports, addresses and photographs can be used in identity fraud or impersonation attempts. Bank details and transaction records can also help criminals make phishing messages or fake requests look more convincing.
Account activity can potentially expose spending patterns, recurring payments, travel, transfers and other financial relationships. In terms of athletes, this could include activity linked to agents, clubs, advisers or sponsors.
The more pieces of information a criminal has, the easier it is to create a believable picture of the victim and use it to target the individual.





























