​Official Italian Email Network Compromised to Access Revolut Accounts in 33 Countries

Rinky Rai
By Rinky Rai - A freelance journalist
4 Min Read

Cybercriminals have targeted approximately 680 Revolut customers by exploiting legitimate government credentials and official email channels rather than breaching the digital lender’s internal technical systems. Posing as law enforcement authorities through an authentic address tied to Italy’s certified government email network, the attackers engaged in communications with Revolut over several months to solicit confidential account records. The operation focused primarily on individuals maintaining substantial cryptocurrency balances, identified through prior blockchain analysis, with customers across 33 nations affected.

Exploiting Certified Government Networks to Target Crypto Balances

​The breach centered on blockchain surveillance used to isolate accounts holding significant digital asset reserves, often described as cryptocurrency whales. After singling out these specific profiles, the perpetrators utilized Italy’s Posta Elettronica Certificata, or PEC, to contact the bank. Because the certified network is legally recognized and designed for secure, verified communications between public bodies, citizens, and businesses, the fraudulent requests carried an appearance of official legitimacy that allowed them to circumvent routine verification protocols.

​Over an extended exchange, the attackers presented their inquiries as formal law enforcement investigations. Initial correspondence sought foundational personal records, including customer names, residential addresses, and telephone numbers. As the interactions progressed, the requests broadened to encompass complete transaction histories, IBAN records, identity documents, and sensitive financial logs. While a substantial share of the exposed accounts belonged to clients based in Switzerland and France, the requests involved account holders across 31 additional jurisdictions.

Security Protocols Challenged by Identity Deception

​Revolut identified the fraudulent correspondence and blocked the originating address, subsequently alerting government officials, regulatory watchdogs, and police agencies alongside notifying the affected customers. The incident has been characterized as an unauthorized disclosure of private records to an external party rather than a direct infiltration of bank infrastructure or a theft of customer funds. Although the perpetrators have since circulated screenshots purporting to show the harvested data, the complete scope and authenticity of the leaked material remain unverified, and the individuals behind the scheme have not been publicly identified.

​Cybercrime specialists observed that the episode underscores the vulnerability of technical safeguards against sophisticated identity-based deception. Former IPS officer and cybercrime expert Prof. Triveni Singh stated that institutions cannot rely entirely on verified email domains to validate data disclosures. He emphasized that financial organizations must implement independent confirmation of the requesting body, authenticate the authority of the specific officer, and maintain multi-layered checks before releasing protected consumer information.

Ongoing Cross-Border Inquiries into Credential Compromise

​Inquiries in Italy are currently directed at establishing how unauthorized users obtained access to the certified state communication platform and dispatched the deceptive legal requests. Detectives are reviewing the precise volume of accounts compromised, the categories of documentation transferred, and whether the gathered files have been deployed or traded for subsequent criminal acts. Analysts warn that pairing real-world identities with verified crypto holdings and past transactional movements leaves high-value investors exposed to targeted social engineering, fraudulent schemes, and identity theft.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected