A Breach That Didn’t Start With Revolut’s Own Systems
Revolut, one of Europe’s most valuable fintech companies, is at the centre of a data breach that has as much to do with the trust placed in government communication channels as it does with the bank’s own cybersecurity. Prosecutors in Reggio Calabria, Italy, have opened a formal investigation after hackers used a compromised or cloned official email account to extract sensitive customer data from the digital bank, before turning around and demanding a ransom to keep it private.
According to Revolut, its own infrastructure and databases were never breached. Instead, the company says it was the victim of a sophisticated social-engineering operation that exploited Italy’s certified email system, known as PEC, which is legally recognised and typically used for binding communications between institutions and businesses. Attackers appear to have used an account linked to the Reggio Calabria prefecture, and possibly Italy’s Interior Ministry, to pose as a legitimate law enforcement authority requesting customer information for what they claimed were ongoing investigations.
Months of Patient, Targeted Requests
What makes this case unusual is the timeline. The group behind the attack, using the online alias “iamnotavillain,” told the Financial Times they began contacting Revolut roughly two months before the breach became public, gradually requesting confidential details on specific customers, including addresses, phone numbers and transaction histories. Revolut, believing it was cooperating with a genuine law enforcement request, complied over an extended period before the fraud was identified.
The targeting was not random. The attackers say they used blockchain analysis to identify Revolut accounts holding substantial cryptocurrency balances, then built a target list of roughly 680 to 700 high-net-worth “crypto whale” clients before requesting their records. Exposed information reportedly includes passport details, driving licences, other identity documents, photographs and, in some cases, transaction histories tied to both fiat and crypto accounts.
From Data Theft to Public Extortion
The situation escalated sharply once the stolen data began appearing online. The hackers launched a dedicated website and began publishing redacted samples of the stolen material, including identity documents connected to publicly recognisable individuals, while demanding roughly $3 million, equivalent to around €2.6 million, to halt further releases. On messaging platform Telegram, the group warned it would continue releasing customer data daily until the ransom was paid.
Revolut has pushed back on aspects of the hackers’ account, stating that its systems remain fully secure and that the incident stemmed entirely from the misuse of an official, state-regulated communication channel rather than any internal compromise. The company says it blocked the compromised email address as soon as the scheme was identified and has since notified both regulators and affected customers directly.
Regulators and Politicians Respond
The fallout has moved quickly beyond Revolut itself. Britain’s Information Commissioner’s Office confirmed it is investigating after Revolut self-reported the incident. In Italy, the national data protection authority has launched checks across the banking sector, urging data-protection officers at other institutions to carry out prompt reviews given the apparent vulnerability in how certified government email requests are verified.
The political reaction in Italy has been particularly sharp. Giulia Pastorella, a member of parliament from the opposition Azione party, described the apparent breach of a ministry email account as deeply alarming and said she intends to raise the matter formally in parliament, questioning how many other organisations may have received similarly fraudulent requests from the same compromised channel.
A Warning for the Wider Financial Sector
Beyond the immediate fallout for Revolut’s affected customers, the episode has exposed a broader weakness that extends well past one company. Many regulated financial institutions place significant trust in official government communication channels with limited independent verification, an assumption this attack appears to have exploited effectively over several months without detection.
Cybersecurity specialists monitoring the case warn that the leaked identity documents and verification photographs significantly raise the risk of identity fraud for those affected, while customers whose cryptocurrency holdings have been exposed face additional privacy and security concerns. As the investigation in Reggio Calabria continues, questions remain over exactly how the government email account was compromised, and whether other companies may have unknowingly handed over sensitive data through the same route.
2 comments
[…] Next Article […]
[…] Next Article […]