started · updated
Revolut data breach affects hundreds via compromised Italian government email
Fintech company Revolut has experienced a sophisticated data breach affecting approximately 680 to 700 customers across multiple European countries, including France, Switzerland, and the UK. The incident was not a direct hack of Revolut’s internal servers; instead, attackers used a procedural deception by compromising a certified email (PEC) account belonging to the Reggio Calabria Prefecture in Italy.
By impersonating Italian law enforcement and using a fake European Investigation Order, the hackers successfully induced Revolut’s compliance department to hand over sensitive information. The compromised data includes identity documents, passports, selfies used for KYC verification, IBANs, bank statements, and transaction histories, including some related to Bitcoin.
An investigation has been launched by the Italian Postal Police, the Reggio Calabria Prosecutor's Office, and the UK's Information Commissioner’s Office. The cybercriminal group 'IAmNotAVillain' has claimed responsibility for the attack and further asserts that they possess approximately 147 GB of internal data from Italian law enforcement agencies, a claim that authorities are currently working to verify. Revolut has stated that customer funds were not affected by the breach.
Entities
IAmNotAVillain · Information Commissioner's Office · Information Commissioner’s Office · Mark Karpelès · Ministero dell'Interno · Polizia Postale · Prefettura di Reggio Calabria · Revolut
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 3 SOURCES] Italian Postal Police and British authorities are investigating the incident. ameve.eu · mail.we-news.com · www.hwupgrade.it
- [● 2 SOURCES] The fraudulent emails passed technical authentication checks such as SPF, DKIM, and DMARC. www.hwupgrade.it · mail.we-news.com
- [● 6 SOURCES] The breach did not involve a direct hack of Revolut's internal servers or the theft of funds. www.hwupgrade.it · forbes.it · ameve.eu · www.republicain-lorrain.fr · www.quotedbusiness.com · +1 more
- [● 12 SOURCES] Criminals used a compromised certified email (PEC) account from the Reggio Calabria Prefecture to target Revolut. www.hwupgrade.it · forbes.it · ameve.eu · www.ilpost.it · mail.we-news.com · +7 more
- [● 7 SOURCES] The cybercriminal group 'IAmNotAVillain' is linked to the operation. forbes.it · www.ilpost.it · www.quotedbusiness.com · www.affaritaliani.it · www.agenpress.it · +2 more
- [● 13 SOURCES] Compromised data included identity documents, selfies, IBANs, bank statements, and transaction histories. www.hwupgrade.it · forbes.it · ameve.eu · www.estrepublicain.fr · www.republicain-lorrain.fr · +8 more
- [● 16 SOURCES] The data breach affected approximately 680 to 700 Revolut customers. www.hwupgrade.it · forbes.it · ameve.eu · www.estrepublicain.fr · www.republicain-lorrain.fr · +11 more
- [● 4 SOURCES] The attackers impersonated the Postal Police to request information via a fake European Investigation Order. forbes.it · www.hwupgrade.it · www.ilpost.it
- [● 3 SOURCES] The hacker group claims to possess 147 GB of Italian law enforcement data. www.quotedbusiness.com · www.affaritaliani.it · www.agenpress.it