Fake Police Emails Tricked Revolut Into Sharing Data

Security Affairs · High sophistication
Last updated September 16, 2026

Threat actors allegedly used a compromised Italian government PEC email account to impersonate law enforcement and send fraudulent information requests to Revolut. Revolut says its systems were not breached, but it received requests that appeared to come from a legitimate government domain and provided customer data in response. About 680 customers were reportedly affected, with exposed data including identity documents, banking details, and transaction history (including crypto).

Key findings

  • Revolut stated its systems were not breached; the company received and acted on fraudulent requests that appeared to come from a legitimate Italian government domain.
  • The compromised account was reportedly a PEC mailbox associated with the Prefecture of Reggio Calabria using the domain pec.interno.it.
  • Attackers allegedly impersonated Italian Postal Police officers and used fraudulent European Investigation Orders to request customer information.
  • Approximately 680 customers were reportedly affected; exposed data allegedly included identity documents, addresses, banking information, account statements, verification selfies, and transaction histories (including cryptocurrency).
  • The attackers allegedly used a “spray and pray” approach by submitting many crypto transaction identifiers and blockchain deposit addresses to identify high-value accounts.
  • A second institutional PEC address was allegedly copied on the requests, potentially to increase credibility.
  • The actor “IAmNotAVillain” claimed broader access to Italian law-enforcement systems and alleged exfiltration of 147 GB, but this was not independently verified.

Who’s being targeted

  • Commonly targeted roles: Legal, Compliance, Fraud Operations, Customer Support (escalations/operations), Security / Trust & Safety, Privacy / Data Protection.
  • Affected industries: Financial services / fintech, Government / law enforcement.
  • Attack channels: email.
  • Impersonated: Italian Postal Police (via compromised Italian government PEC mailbox), Italian government office using PEC (public administration mailbox).

Awareness takeaways

  • Treat ‘trusted sender domains’ as a starting point, not proof, verify the requester’s authority and the legal basis before releasing sensitive data.
  • Flag and escalate unusual volume or patterns in sensitive requests (e.g., repeated crypto-related identifiers) as potential fraud, even if the email looks official.
  • Build a formal out-of-band verification step for law-enforcement/government data requests (e.g., confirmed directory contacts, call-back procedures, and documented approval workflow).
  • Assume mailbox compromise is possible: a compromised government or partner account can be used to attack your organization without ‘hacking’ you directly.

Red flags to watch for

  • Request uses a trusted government domain but seeks unusually broad/large volumes of customer data
  • The requester’s authority/justification does not match the scope (many customers, global spread)
  • Repeated requests focused on crypto transactions and high-value accounts
  • CC’ing another official-looking mailbox is used as “credibility theater” rather than proof of legitimacy
  • Need for original headers/logs to validate whether the message was truly sent by legitimate infrastructure
  • Unusual behavior patterns and scope should trigger enhanced verification
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Revolut wasn’t hacked. They were tricked by what looked like real Italian police emails from pec.interno.it. A compromised PEC mailbox, posing as Italian Postal Police, sent fake European Investigation Orders asking Revolut for IDs, account statements, even crypto transaction history for about 680 customers. Here’s the twist: the emails even CC’d a second official PEC address, making it look like normal government-to-government traffic, while asking for unusually broad data on lots of crypto-heavy accounts. If you ever see a law-enforcement or government email asking for large volumes of customer data, don’t just trust the domain, pause and trigger the out-of-band verification process before sending anything.

Similar attacks

Revolut Users Hit With SMS Phish After Breach

Revolut Users Hit With SMS Phish After Breach

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness”…

September 17, 2026
Revolut Tricked by Fake Government Email

Revolut Tricked by Fake Government Email

Revolut disclosed it was deceived into sharing highly sensitive customer data after receiving fraudulent information requests that appeared to come from a legitimate government email domain. The attacker’s email passed domain authentication, making it harder to detect, and the shared data may…

September 14, 2026
Fake Government Email Tricked Revolut for Data

Fake Government Email Tricked Revolut for Data

Revolut confirmed that an attacker impersonated a government agency using an email address on that agency’s real domain to obtain sensitive customer records. Revolut says only a limited number of customers were affected and that customer funds and Revolut systems were not accessed.

September 14, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Revolut Tricked by Stolen Govt Email

Revolut Tricked by Stolen Govt Email

Attackers used a compromised government email account to pose as authorities and request customer records from Revolut. Employees believed the requests were legitimate and voluntarily sent sensitive customer information, exposing data for nearly 700 people. The incident highlights how “trusted”…

September 18, 2026
Revolut Hit by Govt-Agency Email Impersonation

Revolut Hit by Govt-Agency Email Impersonation

Revolut says a third party posing as a government agency tricked the company into disclosing some customers’ personal and financial data. The attacker used an email address on a legitimate government agency domain, causing the request to be treated as a real legal inquiry. Revolut says customer…

September 14, 2026