Revolut Data Breach Exposed Via Compromised Italian Government Mail System
Hackers infiltrated Revolut by compromising Italy's secure PEC mail system, exploiting forged law enforcement requests to steal personal data from hundreds of cryptocurrency holders.

New details have emerged regarding the massive data breach at British fintech giant Revolut, which compromised the personal information of hundreds of users. Hackers operating under the alias iamnotavillain revealed to the Financial Times via Telegram that they breached Italy's certified electronic mail system, known as La Posta Elettronica Certificata (PEC), using it to impersonate Italian law enforcement agencies over a period of several months.
The Breach Mechanism and Scope
The PEC network is a secure government-supervised messaging system utilized by authorities, corporations, and private citizens for official legal correspondence, functioning as the digital equivalent of registered mail. According to the attackers, they manipulated Revolut by sending fraudulent requests under the guise of official investigations, successfully extracting sensitive data including residential addresses, telephone numbers, and transaction histories for nearly 700 targeted customers.
"Revolut complied with us like good children," one of the hackers claimed, noting that victims were selected using blockchain analytics to identify accounts holding significant cryptocurrency balances.
Impact and Industry Fallout
While the majority of the affected users reside in Switzerland and France, the breached data encompassed clients across 31 additional countries, primarily in Europe. The incident has triggered widespread regulatory concern and customer alarm, particularly given the risk of targeted extortion aimed at securing digital cryptocurrency keys.
The breach comes at a delicate time for Revolut, valued at 115 billion dollars, as the prominent European fintech startup recently secured tentative approval to expand its banking operations into the United States.





