Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
Revolut Data Leak May Trace Back to Compromised Italian Government Accounts 2026-9-16 13:9:22 Author: securityaffairs.com(查看原文) 阅读量:8 收藏

Revolut Data Leak May Trace Back to Compromised Italian Government Accounts

Pierluigi Paganini September 16, 2026

A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers.

The Revolut data exposure may be part of a much broader cyber incident involving compromised Italian government infrastructure.

Revolut has confirmed that its systems were not breached. Instead, the company received fraudulent requests that appeared to originate from a legitimate Italian government domain. The attackers allegedly abused an authentic institutional communication channel to obtain sensitive information on Revolut customers.

According to information reported so far, the compromised account was allegedly associated with the Prefecture of Reggio Calabria and used the pec.interno.it domain. The mailbox was reportedly abused by individuals posing as Italian Postal Police officers.

Databreach @Revolut
Per quale ragioni un dipartimento Enti Locali di una provincia italiana dovrebbe chiedere informazioni finanziarie su clienti sparsi per mezzo mondo? 🤨
A proposito: sono state inoltrate richieste per clienti Revolut italiani? 🤔 pic.twitter.com/oTRKDLlkvA

— Claudio (@sonoclaudio) September 16, 2026

The incident raises an important question: was Revolut deceived, or was the real security failure inside the Italian government infrastructure used to establish the attackers’ identity?

The Financial Times reported that approximately 680 Revolut customers were affected. The information reportedly obtained by the attackers included identity documents, addresses, banking information, account statements, verification selfies and transaction histories, including cryptocurrency transactions.

The attackers allegedly sent Revolut transaction identifiers and blockchain deposit addresses and requested information linking those transactions to specific customers.

Researcher Korra of Duel described the operation as a form of “spray and pray.” According to the analysis, the attackers submitted large numbers of transaction IDs and deposit addresses believed to be associated with high-value Revolut accounts and used fraudulent European Investigation Orders to request customer information.

‼️ BREAKING: Duel can report that the Revolut hacker used a "spray and pray" strategy, sending hundreds of cryptocurrency transaction IDs to Revolut and asking for the associated account details. Revolut complied.

This explains the sheer volume of data the hackers were able to… pic.twitter.com/RqGsuEIkMZ

— Korra (@korraflow) September 15, 2026

The operation appears to have relied heavily on the trust associated with official government communications.

The most concerning element of the case may not be the data obtained from Revolut, but the alleged compromise of Italian law-enforcement infrastructure behind the requests.

The threat actor IAmNotAVillain, which claims responsibility for the operation, alleges that it maintained access for approximately six months to systems belonging to several Italian law-enforcement departments.

The group further claims to have exfiltrated approximately 147 GB of data, allegedly including internal documents, emails, calendars and personal information.

This claim has not been independently verified and should therefore be treated separately from the elements of the Revolut incident that have already been confirmed.

But if the 147 GB dataset exists, its origin could fundamentally change the assessment of the incident.

As researcher @sonoclaudio, who supported my investigation, noted, there is a major difference between compromising a single PEC mailbox and allegedly extracting 147 GB of information from Italian institutional systems.

The first would provide attackers with a powerful tool for impersonation.

The second would indicate a potentially much broader compromise of government infrastructure.

Investigators therefore need to establish where the alleged data originated, which systems were accessed, when the compromise occurred and what information was extracted.

The answers could reveal whether the Revolut operation was an isolated abuse of a government mailbox or part of a longer intrusion into Italian institutional networks.

A second PEC account raises more questions

Another detail could be particularly relevant.

The fraudulent communication sent to Revolut allegedly included a second institutional PEC address in copy.

That detail could have made the request appear more credible. A message originating from an official government address and simultaneously copied to another public administration mailbox can look like a normal exchange between government offices.

But it also raises an obvious investigative question: was the second mailbox compromised as well, or was it simply used as a recipient to reinforce the credibility of the request?

Answering this will require access to the original email headers, PEC logs and authentication records associated with the affected accounts.

Those technical records could help determine whether the messages were actually sent through the legitimate infrastructure, whether the accounts had been taken over and whether other government mailboxes were involved.

The incident highlights a fundamental problem in identity security. An email can be technically authentic and still be fraudulent in a broader sense.

If an attacker controls a legitimate government mailbox, the message may pass technical checks designed to establish its origin. But those controls do not necessarily establish that the individual operating the account is authorized to issue the request.

This distinction between authentication, identity and authorization is critical.

For organizations such as financial institutions, verifying the domain or email infrastructure of a government requester may no longer be sufficient. Requests involving large amounts of sensitive customer information should also be evaluated against additional signals, including the authority of the requester, the legal basis of the request, the scope of the information requested and unusual behavioral patterns.

In the Revolut case, repeated requests involving large numbers of cryptocurrency transactions could potentially have provided additional indicators that warranted closer scrutiny.

How were the Italian accounts compromised?

Another major unanswered question concerns the initial access.

Some reports have referred to infostealers and compromised accounts, but publicly available information is not yet sufficient to establish how the attackers obtained access to the Italian PEC accounts.

It is also unclear whether multifactor authentication was enabled on the affected accounts and whether attackers obtained valid credentials, session tokens or other authentication material.

These details matter because they could determine whether the incident resulted from credential theft, endpoint compromise, weak authentication controls or another attack vector.

The alleged 147 GB dataset should therefore not be presented as an established fact at this stage.

It remains a claim made by the attackers.

But it is a claim that investigators cannot afford to ignore.

If confirmed, the central issue would no longer be limited to the exposure of Revolut customers. Investigators would need to determine whether sensitive Italian government information was stolen before the Revolut operation, during it, or as part of a much broader intrusion.

That could include internal communications, operational information and potentially sensitive material related to law enforcement activities.

For now, the Revolut case demonstrates how a compromise inside one trusted organization can be leveraged to attack another without directly exploiting its infrastructure.

The attackers may not have needed to breach Revolut.

They allegedly compromised the trust surrounding an official government identity, and used that trust as the access mechanism to sensitive financial information.

That is what makes this case particularly significant.

The most important investigation may therefore not be inside Revolut. It may be inside the Italian government systems whose identity was allegedly abused.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Revolut)




文章来源: https://securityaffairs.com/199180/data-breach/revolut-data-leak-may-trace-back-to-compromised-italian-government-accounts.html
如有侵权请联系:admin#unsafe.sh