Cyber & AI intelligence
Wasteland.
Briefs indexed2673
Issues28
Published Mondays07:30 CT
▣ Breach ITALIAN-STATE-EMAI 2026-09-16

Revolut: Hijacked Italian Government PEC Mailbox Used for Fake Law Enforcement Data Requests

"Revolut confirmed on 12 September that sensitive customer data was handed to an unauthorised third party after the fintech received fraudulent data requests sent from a legitimate government email domain, Reuters…"

Revolut confirmed on 12 September that sensitive customer data was handed to an unauthorised third party after the fintech received fraudulent data requests sent from a legitimate government email domain, Reuters reported. The domain in question was pec.interno.it, Italy's Interior Ministry certified email (PEC) infrastructure, and the attackers behind it are now claiming a five-month run of access used to impersonate Italian Postal Police and extract dossiers on Revolut customers, including government-linked individuals. Victim counts differ by source: Financial Times reporting relayed by Security Affairs and Euronews puts the figure at 680 customers, Il Sole 24 Ore says "just under 700," and Cryptobriefing frames it as a range of 680 to 700. Revolut itself has only said a "very limited" number of customers were affected and has not published a number.

What Happened

The mechanism was not a spoofed lookalike domain. According to Security Affairs and the Pillitteri analysis, the requests originated from a genuine Interior Ministry mailbox, reported as [email protected], the Local Authorities office at the Prefecture of Reggio Calabria. Because the mail genuinely left a Ministry server, SPF, DKIM and DMARC all passed. Revolut told CyberInsider that the requests came from a legitimate government agency domain and appeared authentic on every technical indicator its staff had available.

The attackers submitted what looked like emergency data requests and investigation orders. As Marco Ramilli of Yoroi explained to Il Sole 24 Ore, the emergency data request is a routine, high-volume channel that platforms and banks process daily, and compliance with a formally legitimate, binding request from a government body is a GDPR obligation, not a discretionary call. Euronews reports that Revolut supplied files for months before becoming suspicious and checking with Italian authorities, who denied sending the messages, including the Postal Police in whose name the requests were framed. On detection, Revolut says it blocked the address and notified the relevant government agency, law enforcement, data protection and financial regulators.

CyberInsider, citing findings from Duel and Hudson Rock, reports that the campaign initially leaned on forged court orders before shifting focus to Revolut Bank UAB, the group's Lithuania-licensed European entity, with requests framed around European Investigation Orders. Duel says the first successful fraudulent request went out roughly five months before the incident became public. That five-month figure and the infostealer attribution come from OTHER-tier reporting of a single investigative source in contact with a self-described perpetrator, and should be treated as a claim rather than a confirmed finding.

What Was Taken

The data set is unusually complete for identity-fraud and physical-risk purposes. Across Security Affairs, Cryptobriefing and Il Sole 24 Ore, the reported categories include identity documents and passports, home addresses, contact details, banking information and IBANs, account statements, KYC verification selfies, and full transaction histories including cryptocurrency movements.

The targeting logic matters as much as the volume. Duel researcher Korra characterised the operation as "spray and pray": rather than working from a list of known suspects, the attackers sent Revolut large batches of transaction identifiers and blockchain deposit addresses and asked the bank to link them to named customers. In effect, the compromised Ministry mailbox was used as a deanonymisation service against the blockchain. Euronews, citing the FT, notes that the 680 affected customers are spread globally and include several public figures. Revolut has 80 million-plus customers worldwide and about 5 million in Italy on Milano Finanza's estimate, so the affected set is a tiny but highly selected fraction.

Revolut has been consistent on scope: its own systems were not breached and customer funds were unaffected.

Why It Matters

This is a supply-chain failure in the trust fabric of lawful-access requests, not a conventional bank intrusion. Every control Revolut had at the point of decision returned a green light, because the sender was real. The compromise happened one layer upstream, inside a government mailbox that financial institutions, platforms and telecoms are structurally obliged to trust.

Three consequences follow. First, a single infostealer log for a low-profile regional prefecture office can be converted into an authenticated request channel against any regulated entity in the EEA. Second, GDPR and European Investigation Order frameworks create legal pressure to comply quickly, which the attackers exploited directly. Third, the exfiltrated combination of identity documents, selfies and crypto transaction graphs is the highest-value package available for account takeover, exchange KYC bypass and extortion against named individuals.

The extortion follow-on is where OTHER-tier sourcing dominates. CyberInsider and Cryptobriefing both report a demand of 10,000 Bitcoin, valued at roughly $782 million at the time, with a threat to publish more customer data. Cryptobriefing attributes the campaign to a Telegram handle "I Am Not A Villain" and reports that samples were circulated online and that affected individuals were extorted directly. Neither the actor identity nor the ransom figure has been confirmed by Revolut or Italian authorities.

Investigations are running on multiple fronts: Italy's Polizia Postale on charges of abusive access to a computer system and computer fraud, with involvement from the Agenzia per la Cybersicurezza Nazionale, and the UK privacy regulator following Revolut's own report.

The Attack Technique

Per Duel and Hudson Rock via CyberInsider, initial access to government employee mailboxes came from infostealer malware, meaning credential theft from an endpoint rather than any flaw in the PEC platform itself. The post-access tradecraft is the notable part and is built entirely around staying invisible to the legitimate mailbox owner:

That pattern produces a mailbox that looks completely normal to its owner while functioning as an active law-enforcement impersonation platform. Screenshots published with the investigation show the Revolut correspondence originating from pec.interno.it addresses. Detection, in this model, depends almost entirely on the recipient noticing anomalies in request content, not on the compromised organisation noticing anything at all.

What Organizations Should Do

  1. Treat domain authentication as insufficient for lawful-access requests. SPF, DKIM and DMARC prove the server, not the sender's authority. Require out-of-band verification against a pre-established contact directory for the requesting agency before any disclosure, and make that step mandatory rather than discretionary.
  2. Instrument emergency data request workflows for volume and pattern anomalies. A local-authority office asking for financial records on customers across multiple jurisdictions, or submitting hundreds of blockchain addresses in bulk, is a behavioural red flag that no authentication check will ever raise. Rate-limit and escalate per requesting mailbox.
  3. Audit mailbox recovery addresses, forwarding rules and delegation across all staff accounts, especially in public-sector environments. Persistence via an added recovery address survives password resets and is trivial to miss.
  4. Alert on mail-deletion patterns, not just logins. Sent-item deletions immediately after send, and bulk .eml downloads followed by deletion, are the observable signature here. Preserve server-side audit logs independently of the user-visible mailbox.
  5. Enforce phishing-resistant MFA and continuous infostealer log monitoring for any account attached to a certified or institutional mail domain. Treat appearance in a stealer-log feed as an active compromise, not a password-rotation ticket.
  6. If you hold KYC selfies and identity documents, assume they are reusable credentials. Customers exposed here should be flagged for elevated-friction verification and step-up checks, since the attackers now hold everything a standard remote identity check asks for.

Sources: Hackers say they breached Italian state email to target ... | Revolut Data Leak May Trace Back to Compromised Italian Government... | Revolut confirms sensitive customer data breach after fake governme... | Revolut hackers used infostealer to hijack Italian government emails | Hacked Reggio Calabria Mailbox Named in the Revolut Breach | Hackers breach Italian state email to target Revolut crypto users | Revolut hands over the details of 700 customers to fraudsters ... | Revolut subisce una truffa via Pec in Italia e consegna dati person...