šŸ”šŸ“© Government PEC Phishing Exposes 680 Revolut Customers

šŸ”šŸ“© Government PEC Phishing Exposes 680 Revolut Customers
680 Revolut customers' passports, selfies, bank data & Bitcoin histories were exposed via a phishing attack that hijacked Italian government PEC email accounts. šŸ’¼ The request looked fully official; the legal channel authenticated the machine—not the person. Attackers demanded 10,000 BTC (~$782M). No internal breach was found, but stolen crypto histories give scammers precise social-engineering hooks. As the ICO opens an investigation and Polizia Postale digs into compromised mailboxes, regulators face a hard question: how do you verify the human behind a legitimate-looking request? šŸ” If Revolut's compliance desk can't tell real from impersonated—can yours? What should fintechs add before sharing data on a "valid" request?

On September 12, a seemingly routine request arrived at Revolut's compliance desk. It appeared to come from the Prefecture of Reggio Calabria, an Italian government office, delivered through Italy's certified electronic mail system (PEC). The domain was legitimate, the authentication passed, and the legal standing of the channel carried weight. Staff processed the request—and handed over sensitive records for 680 customers, including passports, verification selfies, bank details, addresses, and Bitcoin transaction histories.

It was a sophisticated impersonation attack, and it worked.

A Target Made for Trust

The mechanics trace back to compromised Italian government email accounts on the pec.interno.it domain. Italian authorities and CERT-AGID had flagged PEC abuse months earlier—roughly 650 such cases were reported in early 2026 alone—yet the channel retains legal legitimacy that financial firms are structurally inclined to honor. The reported threat environment across Italy has indeed sharpened: cybersecurity incidents rose across banking, judiciary, and technology sectors following June events, from an Intesa Sanpaolo's €30.6 billion bid for Monte dei Paschi to renewed EU sanctions drawing cyber-risk warnings. Notably, Italy acted early on NIS-2 transposition while 23 member states still missed the deadline by July, yet even that head start did not protect the PEC channel from abuse.

Revolut investigators confirmed the attackers used infostealer malware to compromise the mailboxes, granting them the ability to add recovery addresses, read ongoing correspondence, and even delete fraudulent outgoing messages to cover their tracks. The campaign ran for roughly five months, and Italian CERT-AGID field data corroborates the scale of the abuse—investigators found approximately 300 compromised credentials circulating in cybercrime databases, and the threat actor, identifying as IAmNotAVillain, claimed six months of operational control over Italian law-enforcement systems.

What Was Taken

The exposed data is not a small set of email addresses. It amounts to complete identity-theft kits: government-issued ID copies, address histories, IBANs, transaction histories, and Bitcoin wallet references. Several high-profile individuals were among the 680 affected, including tennis player Alexander Shevchenko, Gamdom CEO Felix Römer, and former Mt. Gox chief executive Mark Karpelès, who posted tampered email excerpts on X.

Revolut maintains that its core systems and customer funds were never touched—no internal breach occurred. But the personal exposure is materially worse than a login credential dump. Affected customers now face heightened identity-fraud and targeted-phishing risk, particularly given that stolen cryptocurrency transaction histories give attackers unusually specific hooks for social engineering.

The Ransom and the Response

The attackers followed with an extortion demand: 10,000 Bitcoin (roughly $782 million at current prices) in exchange for not publishing further data. Telegram channels published leaked records for high-profile clients, alongside the unverified claim that roughly 147GB of internal Italian police materials were also in the attacker's possession—archives they say include documents, calendars, and internal chat logs spread across 30+ countries.

Revolut blocked the source address, notified affected customers, and alerted the Italian government agency, enforcement bodies, data-protection authorities, and financial regulators. The UK's Information Commissioner's Office (ICO) has opened a formal investigation into the handling of the requests, while Italy's Polizia Postale is examining the compromised government mailboxes. The broader implication is that any valid government request on PEC could be redirected to attackers.

What This Signals for Verification

The pattern exposes a clear weakness: authentication and legal standing are not the same as verification. A request that passes email authentication is technically valid, but nothing in the PEC system authenticates the human operator behind a compromised or hijacked mailbox.

  • Near term: Expect heightened phishing activity against the 680 affected customers and scrutiny of how fintechs triage government data requests.
  • Medium term: Regulators in the UK and EU are likely to tighten standards for cross-agency validation before data is released—the ICO investigation will set precedent.
  • Long term: Government digital channels that carry legal weight will need stronger post-compromise detection—the PEC system concedes it detects account misuse only after abuse occurs.

The Revolut incident is not a story of broken cryptography. It is a story of trust architectures built on channels that authenticate machines, not people—and what happens when that gap is exploited.