Commenta La Notizia

The Revolut Data Scandal: How Fake Government Requests Exposed Hundreds of Customers

Revolut faces a major data breach involving around 680 customers after fraudulent requests allegedly used a compromised Italy

The Revolut story is not a typical hacking case.
There was no dramatic image of criminals breaking through a bank's main servers, no public evidence of customer accounts being emptied and, according to Revolut, no compromise of the company's internal systems or customer funds.
Instead, the story appears to have revolved around something much simpler and potentially much more worrying: trust.
Hackers allegedly used a compromised Italian government email channel to make fraudulent requests that appeared to come from law enforcement. Revolut then provided sensitive information relating to around 680 customers.
The incident has since developed into a ransom story, with the group claiming responsibility demanding $3 million in cryptocurrency and threatening to sell the stolen information.
There is also another, much more serious claim: the same group says it obtained around 147 GB of data belonging to Italian law-enforcement systems.
That claim has not been independently confirmed and remains under investigation.


Revolut sotto attacco Foto 2.png


This was not simply a hack of Revolut


The distinction matters.
Revolut has confirmed that unauthorised people obtained customer information after fraudulent requests were made using what appeared to be a legitimate government domain.
According to the company's explanation, the attackers did not need to break directly into Revolut's core infrastructure. Instead, they allegedly abused a trusted communication channel and presented themselves as a legitimate law-enforcement authority.
That is what makes the incident so unusual.
Financial institutions routinely receive legally valid requests from governments and law-enforcement agencies. The problem in this case appears to have been that the criminals were able to make a fraudulent request look sufficiently legitimate to pass through the process.


Around 680 customers were affected


The information involved is highly sensitive.
Reports indicate that the stolen material included identity documents, addresses, photographs used for identity verification, account information and transaction histories, including cryptocurrency activity.
Revolut has said that customer funds were not affected and that its systems were not directly breached.
That is important because it changes the immediate risk.
The story is not currently about hackers gaining direct access to customer balances and transferring money out of accounts. The more obvious danger is what criminals can do with personal information after obtaining it.


Why the stolen data matters


A passport or identity document may not sound as dangerous as a password, but in the hands of a criminal it can be extremely useful.
Combine an identity document with an address, financial information and transaction history and you have the ingredients for much more convincing fraud.
The most immediate concern is targeted phishing.
A generic scam email is relatively easy to recognise. A message that contains genuine information about you is much harder to dismiss.
A criminal who knows your name, where you live and something about your financial activity can construct a much more believable story when contacting you.
That could eventually be used to obtain passwords, authentication codes or authorisation for a transaction.
This is why a data breach can remain dangerous long after the original incident has been contained.


The ransom demand


The story became even more serious when the group calling itself IAmNotAVillain published a ransom demand.
The amount was $3 million in cryptocurrency, with the attackers threatening to sell the stolen data if the payment was not made.
The Post reported that the group gave Revolut 24 hours from the evening of September 16 to respond.
There is, however, an important distinction.
Revolut has said that it did not receive a direct ransom demand from the attackers. The demand was published through channels controlled by the group claiming responsibility.
That means it would be inaccurate to describe the situation as an established negotiation between Revolut and the hackers.
It is more accurate to say that a public ransom demand was issued by the group claiming responsibility for the breach.


Revolut sotto attacco Foto 3.png


The 147 GB claim is even more serious


The most alarming part of the story may not actually involve Revolut.
The group says it also obtained approximately 147 GB of data from Italian law-enforcement systems, including internal documents and communications.
That claim has been reported by Italian media and international outlets, but it remains a claim by the attackers.
Italian authorities are investigating the possible compromise of an institutional PEC connected to the Prefecture of Reggio Calabria. Investigators have not established that an entire government computer system was compromised.
That distinction matters.
At this stage, the public record supports the existence of an investigation into the misuse or compromise of an institutional communication channel. It does not justify stating as fact that 147 GB of Italian police data have definitely been stolen.
If investigators confirm the claim, the significance of the incident would obviously increase dramatically.


The PEC problem


The case has also triggered a broader discussion about the security of Italy's certified email system.
AgID has acknowledged that it has observed an increase in the compromise and illicit use of PEC accounts in recent months.
The agency is also working on the transition toward a Qualified PEC, or PEC Q, which is intended to provide additional security features within the European eIDAS framework.
The broader lesson is uncomfortable but straightforward: a secure communication channel is only as strong as the procedures surrounding it.
Even if the technology itself works correctly, a compromised account can still become a tool for impersonation.


The privacy authorities are now involved


The Italian Data Protection Authority has started checks into possible vulnerabilities affecting the way Italian banks handle requests for customer information from authorities.
That is an important development because the potential problem is not necessarily unique to Revolut.
If criminals can obtain control of a trusted institutional communication channel and use it to make apparently legitimate requests, the same basic technique could potentially be attempted against other financial institutions.
The Italian authority has also been exchanging information with its Lithuanian counterpart, where Revolut has its main legal headquarters.
The case therefore has a European dimension as well as an Italian one.


What Revolut customers should actually worry about


There is no reason for customers to panic simply because they have a Revolut account.
According to the company, customer funds were not touched.
The more immediate concern is the possible use of personal information for targeted scams.
Customers should therefore be particularly cautious about unexpected calls, emails or messages claiming to come from Revolut.
No legitimate support interaction should require a customer to reveal passwords, PINs or authentication codes simply because someone claims to be calling about the incident.
The safest approach is to stop the conversation and contact the company independently through its official channels.
That advice is not revolutionary, but after a breach involving highly detailed personal information, it becomes much more important.


The real lesson is bigger than Revolut


There is an understandable temptation to look at this story as another example of hackers attacking a financial company.
I think the more interesting lesson is different.
The alleged attackers did not necessarily need to defeat Revolut's strongest technical barriers. They needed to convince the company that the person asking for the data was legitimate.
That changes the cybersecurity conversation.
Banks and fintech companies need strong infrastructure, of course. But they also need procedures capable of identifying when a trusted communication channel has itself become untrustworthy.
The same applies to government institutions.
A compromised email account is not simply an email problem if that account can be used to impersonate a law-enforcement authority.


An investigation that is still unfolding


Several parts of the story are now reasonably clear.
Revolut has confirmed the unauthorised disclosure of sensitive information involving around 680 customers.
Italian authorities are investigating the institutional email channel involved in the requests.
Revolut says customer funds and its internal systems were not compromised.
A $3 million ransom demand has been publicly attributed to the group claiming responsibility.
But the wider claim concerning 147 GB of Italian police data remains unverified.
That last point should remain at the centre of the reporting.
Cybersecurity stories move quickly, especially when criminals publish their own claims online. The temptation is to repeat every new statement immediately.
The more responsible approach is to separate what has been confirmed from what is still being investigated.
And in the Revolut case, that difference is enormous.
The most troubling question may ultimately have little to do with cryptocurrency or even with Revolut itself.
It is whether, in a digital world where institutions increasingly trust electronic identities, we have built systems capable of recognising when someone has stolen the identity of the institution we are supposed to trust.


Revolut sotto attacco Foto 4.png


👉 Want to read the full original article? Read it on Commenta La Notizia:👇
https://www.commentalanotizia.com/2026/09/revolut-attacco-hacker-furto-dati-pec.html
The original article is in Italian. You can use your browser’s automatic translation feature if needed.


Subscribe and vote for all articles 👇
https://www.publish0x.com/goldweb?a=xkazKWYYbJ


💬 Join us on Telegram to comment and follow all the insights
👉 https://t.me/CommentaLaNotizia


© 2026 Commenta la Notizia - All rights reserved
Official sources used under fair use


📺 Follow Commenta La Notizia for deeper insights, global analysis, and fearless discussions about the issues that shape our world — from politics and technology to society and the hidden forces behind the headlines.
⚠️ Legal Notice This article and the related multimedia content are the exclusive property of the author. Copying, reproduction, distribution, or modification in any form or on any platform is prohibited without written permission.
Copyright © CondividiSulWeb – YouTube Commenta La Notizia


👤 Author: @condividisulweb


✍️ Commenta La Notizia is my editorial project created to provide clear and engaging insights into news, events, and major current issues.
Every article, video, and short is made with a clear goal: not only to inform, but also to give context, reflection points, and analysis to understand not just what happens, but especially why it happens.
With Commenta La Notizia I want to build a reliable and accessible space where everyone can get informed, understand, and join the discussion.
🌐 If you want to stay updated, you can follow me here.
💬 Your opinion matters! Every piece of news is a chance to discuss: share your thoughts and make your voice heard.
📰 Comment, share, stay informed.

🙏 Thank you for reading: your time and your opinion are the true value



✍️ SUPPORT FREE INFORMATION✍️


⚠️REMEMBER, YOU CAN VOTE ON ALL ARTICLES EVERY HOUR
AND REGISTER FOR FREE TO VOTE!⚠️


👇👇👇👇 😍 HELP GROW MY PASSION😍 👇👇👇👇


Publish0x Blog

Official Blog (Original Complete Articles)

Blurt Blog

Facebook Page

X Page

Youtube Channel

Telegram Channel

How do you rate this article?

4


CondividiSulWeb
CondividiSulWeb

Want to support my project? Then subscribe to our YouTube channel too: 🔴 https://www.youtube.com/@CommentaLaNotizia 🔴 Remember to comment on our videos and leave a LIKE.


Commenta La Notizia
Commenta La Notizia

🔷 Official Bio – Commenta La Notizia 🎙️ News that get people talking. 📰 Crypto • Finance • Gossip • Current Events • Breaking News & more. 🌍 From Italy to the world. 💬 Comment. Share. Reflect. 📲 Follow us and never miss a beat. 📢 Your opinion matters.

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?