Threat actors allegedly used a compromised Italian government PEC email account to impersonate law enforcement and send fraudulent information requests to Revolut. Revolut says its systems were not breached, but it received requests that appeared to come from a legitimate government domain and provided customer data in response. About 680 customers were reportedly affected, with exposed data including identity documents, banking details, and transaction history (including crypto).
Key findings
- Revolut stated its systems were not breached; the company received and acted on fraudulent requests that appeared to come from a legitimate Italian government domain.
- The compromised account was reportedly a PEC mailbox associated with the Prefecture of Reggio Calabria using the domain pec.interno.it.
- Attackers allegedly impersonated Italian Postal Police officers and used fraudulent European Investigation Orders to request customer information.
- Approximately 680 customers were reportedly affected; exposed data allegedly included identity documents, addresses, banking information, account statements, verification selfies, and transaction histories (including cryptocurrency).
- The attackers allegedly used a “spray and pray” approach by submitting many crypto transaction identifiers and blockchain deposit addresses to identify high-value accounts.
- A second institutional PEC address was allegedly copied on the requests, potentially to increase credibility.
- The actor “IAmNotAVillain” claimed broader access to Italian law-enforcement systems and alleged exfiltration of 147 GB, but this was not independently verified.
Who’s being targeted
- Commonly targeted roles: Legal, Compliance, Fraud Operations, Customer Support (escalations/operations), Security / Trust & Safety, Privacy / Data Protection.
- Affected industries: Financial services / fintech, Government / law enforcement.
- Attack channels: email.
- Impersonated: Italian Postal Police (via compromised Italian government PEC mailbox), Italian government office using PEC (public administration mailbox).
Awareness takeaways
- Treat ‘trusted sender domains’ as a starting point, not proof, verify the requester’s authority and the legal basis before releasing sensitive data.
- Flag and escalate unusual volume or patterns in sensitive requests (e.g., repeated crypto-related identifiers) as potential fraud, even if the email looks official.
- Build a formal out-of-band verification step for law-enforcement/government data requests (e.g., confirmed directory contacts, call-back procedures, and documented approval workflow).
- Assume mailbox compromise is possible: a compromised government or partner account can be used to attack your organization without ‘hacking’ you directly.
Red flags to watch for
- Request uses a trusted government domain but seeks unusually broad/large volumes of customer data
- The requester’s authority/justification does not match the scope (many customers, global spread)
- Repeated requests focused on crypto transactions and high-value accounts
- CC’ing another official-looking mailbox is used as “credibility theater” rather than proof of legitimacy
- Need for original headers/logs to validate whether the message was truly sent by legitimate infrastructure
- Unusual behavior patterns and scope should trigger enhanced verification
Read the video transcript
Revolut wasn’t hacked. They were tricked by what looked like real Italian police emails from pec.interno.it. A compromised PEC mailbox, posing as Italian Postal Police, sent fake European Investigation Orders asking Revolut for IDs, account statements, even crypto transaction history for about 680 customers. Here’s the twist: the emails even CC’d a second official PEC address, making it look like normal government-to-government traffic, while asking for unusually broad data on lots of crypto-heavy accounts. If you ever see a law-enforcement or government email asking for large volumes of customer data, don’t just trust the domain, pause and trigger the out-of-band verification process before sending anything.