Hackers compromised a certified Italian government email account and used it to trick Revolut into handing over customer passports, verification selfies and transaction histories, Italian cybercrime police confirmed September 15. Revolut says its systems and customer funds were not breached, the attackers impersonated an official institution rather than hacking the fintech directly.
Italy’s cybercrime police investigate compromised government account
The investigation is focused on how the government email account was compromised and how the attackers were able to use it to obtain customer data. ANSA said the requests initially did not raise suspicion because they appeared to come from an official institutional address.
Italian media reports have identified the potentially compromised account as one belonging to the Prefecture of Reggio Calabria. However, that identification has not been confirmed by Revolut, and the company has declined to name the government agency involved while the police investigation remains active.
That distinction matters because the available evidence points to misuse of a legitimate account, not a direct intrusion into Revolut’s systems. The Revolut data leak involved information being disclosed in response to fraudulent requests, according to reporting on the incident and the company’s statement.
Sensitive customer information reportedly exposed
The information reportedly obtained by the attackers was highly sensitive. Cointelegraph reported that the exposed material included copies of passports, verification selfies and complete transaction histories belonging to some customers.
However, there is no indication from the sources reviewed that customer funds were transferred or that Revolut’s banking databases were breached.
Revolut said the number of affected customers was limited and that it had contacted those individuals. The company also said it had reported the incident to relevant authorities after detecting the fraudulent activity.
The Revolut data leak highlights a different type of cybersecurity weakness: the abuse of trust in official communications. Instead of breaking through a financial institution’s technical defenses, an attacker can attempt to make a fraudulent request appear legitimate by controlling or compromising an account associated with a government domain.
Italy’s PEC system faces wider abuse
The Revolut data leak also comes as Italian authorities warn about broader abuse of Posta Elettronica Certificata, or PEC. The system provides certified electronic delivery and gives messages legal value comparable to registered mail, but Italy’s CERT-AGID has emphasized that certification of delivery does not mean the content itself is safe.
In a June 15 advisory, CERT-AGID said it had handled more than 650 events involving PEC mailboxes that were abused or created for illicit purposes between January and the date of the report. The agency said the figure was increasing during the year and warned that legitimate PEC accounts can be compromised.
CERT-AGID specifically cautioned that a PEC message can still contain malicious links, infected attachments or other forms of fraud. Its guidance urges recipients not to open unexpected attachments or click suspicious links and to report suspected abuse to their PEC provider and the agency.
The incident puts that warning into a financial-services context. A trusted government email address can create a powerful layer of credibility, potentially allowing a fraudulent request to pass checks that would otherwise block an unknown sender.
What happens next in the investigation
Italian investigators now have to determine who controlled the compromised account and what customer information was obtained. The authorities are also expected to determine whether the incident was isolated or connected to the wider abuse of PEC accounts documented by CERT-AGID.
For Revolut customers, the company’s current position is that its systems and customer funds were not affected. The immediate concern is the misuse of personal information belonging to the limited group of customers whose data was disclosed.
The Revolut data leak also illustrates why authentication based only on a sender’s domain can be insufficient when an account itself has been compromised. Government addresses may carry legal and institutional authority, but as CERT-AGID’s warnings show, that does not guarantee that every message sent from a legitimate PEC account is trustworthy.
The case may also test how financial firms validate requests for customer records when those requests appear to come from public authorities. The investigation could provide a clearer picture of where identity verification failed and what additional controls may be needed when a trusted institutional mailbox has itself been compromised.
As the Polizia Postale continues its investigation, the key unanswered questions remain the scope of the exposed information, the method used to compromise the government account and whether additional organizations received fraudulent requests from the same source.