< Back to all clusters
[TECHNOLOGY] · Italy, United Kingdom, France, Switzerland · 22 sources

started · updated

Revolut data breach affects hundreds via compromised Italian government email

Fintech company Revolut has experienced a sophisticated data breach affecting approximately 680 to 700 customers across multiple European countries, including France, Switzerland, and the UK. The incident was not a direct hack of Revolut’s internal servers; instead, attackers used a procedural deception by compromising a certified email (PEC) account belonging to the Reggio Calabria Prefecture in Italy.

By impersonating Italian law enforcement and using a fake European Investigation Order, the hackers successfully induced Revolut’s compliance department to hand over sensitive information. The compromised data includes identity documents, passports, selfies used for KYC verification, IBANs, bank statements, and transaction histories, including some related to Bitcoin.

An investigation has been launched by the Italian Postal Police, the Reggio Calabria Prosecutor's Office, and the UK's Information Commissioner’s Office. The cybercriminal group 'IAmNotAVillain' has claimed responsibility for the attack and further asserts that they possess approximately 147 GB of internal data from Italian law enforcement agencies, a claim that authorities are currently working to verify. Revolut has stated that customer funds were not affected by the breach.

Entities

IAmNotAVillain · Information Commissioner's Office · Information Commissioner’s Office · Mark Karpelès · Ministero dell'Interno · Polizia Postale · Prefettura di Reggio Calabria · Revolut

Claims

What the coverage asserts, and how many sources carry each claim.

Sources

about 8 hours ago