← All posts

Security

Nobody Broke Into Revolut. Someone Sent It Police Paperwork From a Stolen Government Mailbox

Around 680 Revolut customers had passports, verification selfies and account statements handed to criminals who spent five months impersonating Italian police. Revolut's systems held. The process that answers law enforcement did not.

MAI
Revolut's official brand image from the company's own website, showing the Revolut wordmark.

Revolut has confirmed that data belonging to roughly 680 European customers was obtained by criminals who never touched its infrastructure. They asked for it. The requests arrived from a hijacked Italian government mailbox, dressed as law enforcement paperwork, and Revolut answered them for about five months.

This is not a vulnerability story. There is no CVE, no patch, no version table. The failure is in a channel that every bank, exchange and platform operates and almost nobody treats as a security boundary: the desk that answers requests from police.

What was handed over

The requests went to Revolut Bank UAB, the group's Lithuania-registered banking entity, and were made in the name of Italy's Postal Police. According to Security Affairs, the sending account was associated with the Prefecture of Reggio Calabria on pec.interno.it, the Interior Ministry's certified-email domain, and the requests took the form of European Investigation Orders — the cross-border instrument EU authorities use to compel evidence from another member state. The targets were selected by submitting batches of cryptocurrency addresses and asking who was behind them.

Customers affected~680, described by Revolut as European
Entity that received the requestsRevolut Bank UAB (Lithuania)
Duration before disclosure~5 months
ImpersonatedItalian Postal Police, via a Ministry of the Interior PEC mailbox
Data obtainedIdentity documents, addresses, banking details, account statements, verification selfies, transaction histories
Extortion demand$3 million, or 6,000 XMR, with a 24-hour deadline
Customer fundsNot affected, per Revolut

Revolut says its internal systems and customer funds were not compromised, that it blocked the offending address once it detected the activity, and that it has contacted the affected customers. On the extortion attempt, the company told SecurityWeek:

Revolut has not received any direct contact or demand from the individuals or group making these claims.

The actor, using the alias "IAmNotAVillain," published the demand instead, threatening to sell the material on.

The mailbox was the whole credential

Italy's PEC system is legally recognised certified email, which is exactly why a message arriving from pec.interno.it carried the weight it did. The compromise behind it was mundane. CyberInsider reports that Hudson Rock found roughly 300 credentials for that domain sitting in commodity infostealer logs — the same stolen-password dumps that feed ordinary account takeovers. No one needed to breach the Ministry of the Interior. They needed one official whose machine had been infected, and a market that resells the results for pocket money.

That is the asymmetry worth sitting with. A bank spends heavily on authentication, fraud scoring and transaction monitoring, and then exposes an inbox where the identity check is, in practice, the sender's domain and whether the document looks right.

The request desk is production access

A law enforcement response function is an access path into the most sensitive data a financial institution holds: identity documents, balances, counterparties, movement. It is usually staffed as a legal or compliance workflow rather than an engineering one, which means it inherits none of the controls that any other route to that data would require — no strong authentication of the requester, no rate limiting, no anomaly detection when one source suddenly submits hundreds of lookups, no audit path that anyone reviews.

The obvious fixes are unglamorous and largely procedural. Verify the requesting officer out of band, against a number the agency publishes rather than one supplied in the request. Treat a spike in volume from one origin as an incident signal, not a workload problem. Log disclosures where a security team can see them. Several of these would have collapsed the five-month window to days.

There is also a regulatory question that Europe has not answered. Italian prosecutors in Reggio Calabria have opened an investigation, the National Anti-Mafia and Counter-Terrorism Directorate is involved, and Italy's data protection authority has opened checks and contacted its Lithuanian counterpart, according to Euronews. Nobody yet owns the standard for authenticating a cross-border legal request, and until someone does, the trust model is the sender's email domain.

What the affected should assume

For the 680, the practical exposure is durable rather than immediate. Passports, driving licences and verification selfies do not rotate. That material is the raw input for account-opening fraud and for SIM-swap and support-desk impersonation at other providers, and it stays useful for years. Anyone notified should expect targeted, well-informed social engineering that cites real account details, and should treat unsolicited contact referencing this incident as hostile by default.

One claim remains unverified: the same actor says they held access to Italian law enforcement systems for around six months and took roughly 147GB of internal material. That is the attacker's assertion, reported but not confirmed, and investigators have not corroborated the figure.

Sources: SecurityWeek · Security Affairs · Euronews · CyberInsider

Keep reading