Your privacy choices

We use analytics to improve Pollar and, with your consent, marketing tools (Meta, X) to measure our ads. You can change this anytime in Settings.

Privacy policy
Pollar
HomeAskLiveBriefOriginalsSearchMapMarketsNotificationsFor You
ThreadsMarkets
NewsroomSupport Pollar
Privacy
Reader-supported

Free to read, and staying that way

No ads. Membership keeps Pollar independent.

from$2.99/mo

Support Pollar
Membership

Members don't see this panel.

  • Supporter$2.99/mo
  • Founder$6.99/mo
Support Pollar

Today’s Brief

The Fed raises rates again

Warsh tightens money as Gaza deaths expose shelter risks and Europe courts Canada

The last half-day brought a harder economic tone and a grim reminder of what prolonged wars do to civilians. The Federal Reserve raised rates for the first time since 2023, while rescue crews in Gaza searched a collapsed apartment block with little more than hand tools.

Read the Brief

Live now

All live coverage
  • US-EU tensions over Canada associate status

    Threatens Donald Trump to halt trade with the EU if the bloc proceeds with associate membership for Canada, labeling the potential move an act of hostility.

  • US passes Russia sanctions amid Kyiv strikes

    House passes sanctions package 262-159 and sends it to Trump as explosions damage buildings in Kyiv.

In the spotlight

All threads

European Union · Updated 1h ago

Brussels vs capitals: EU integration

No new discrete occurrences; findings add detail and reaction to already-chronicled proposals.

HomeBriefThreadsAsk
Categories
AI-generated·Learn how
© ANSA.it
Digital·33m ago

Hackers obtain data on 680 Revolut customers using compromised Italian government email

Italian prosecutors and British regulators opened investigations after cybercriminals used a certified email account belonging to the Reggio Calabria Prefecture to obtain sensitive customer records from digital bank Revolut.

Deceptive requests and internal handovers

Cybercriminals operating under the moniker "iamnotavillain" obtained sensitive data belonging to 680 Revolut customers across several European countries by impersonating Italian law enforcement personnel. Over several months, the perpetrators transmitted fraudulent records requests through a certified electronic mail (PEC) address registered to the Reggio Calabria Prefecture. The requests were delivered to Revolut's Lithuanian banking entity rather than its Italian office, citing fabricated criminal proceedings linked to the Milan Prosecutor's Office and referencing European Investigation Orders.

Correspondence between the perpetrators and Revolut revealed several structural discrepancies in the requests. The fraudulent filings paired a southern Italian prefecture address with a Milan judicial inquiry and displayed incorrect protocol numbers tied to the Rome Prosecutor's Office. On 24 March 2026, Revolut compliance staff instructed the scammers to adjust their document headers to satisfy standard processing requirements. Following delays in May 2026 attributed to an internal review, Revolut confirmed on 24 July 2026 that it had transmitted the files, with decryption keys supplied separately. Transferred materials included passports, national identity cards, verified photographs, home addresses, bank account details, and Bitcoin transaction records. Revolut noted during processing that 169 requested accounts belonged to United Kingdom jurisdiction, requiring separate judicial requests.

Timeline of fraudulent data requests to Revolut
  1. Mar 24, 2026Revolut compliance staff ask scammers to reformat request headers
  2. 2026-05Revolut notes document delivery delays due to an internal audit
  3. Jul 24, 2026Revolut confirms transfer of requested customer data files
  4. Sep 16, 2026Italian prosecutors and British regulators open data breach inquiries

Regulatory and judicial investigations

The Public Prosecutor's Office of Reggio Calabria opened a criminal inquiry under Article 615 ter, paragraph 3, of the Italian penal code, covering unauthorized access to public-interest computer systems. Postal Police investigators are examining whether the certified email account was infiltrated directly or cloned by the attackers. Italian authorities noted that investigators possess no confirmation that physical computers at the prefecture or the Viminale headquarters of the Ministry of the Interior were compromised.

The National Anti-Mafia and Counter-Terrorism Directorate stepped in to oversee the case under protocols activated when government bodies face digital intrusions. The hacker collective contacted the Financial Times via Telegram and shared email screenshots, claiming to hold 147 gigabytes of internal Italian police data, agency chats, and administrative documents. The group demanded a financial ransom from Revolut under threats of publishing customer records, prompting dark web monitoring by European law enforcement. In the United Kingdom, the Information Commissioner's Office launched a formal investigation after Revolut reported itself to British authorities.

Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators.

— Revolut

Support independent Pollar

Supporter and Founder memberships keep every article free to read, and add offline reading, audio, and a sponsor-free brief.

See membership tiers

Systemic vulnerabilities and banking safeguards

Italian privacy authority Garante launched an inspection of access protocols across domestic financial institutions to identify potential system vulnerabilities. The regulator sent formal advisories to bank data protection officers, requesting immediate internal audits and rapid escalation of any detected breaches. The agency also coordinated with Lithuanian privacy regulators overseeing Revolut's primary European license and engaged the Ministry of the Interior to evaluate weaknesses in official PEC infrastructure.

Customer profiles involved in Revolut data disclosure · profiles
Total customer profiles transferred
680
Profiles flagged under UK jurisdiction
169
Total customer profiles transferred
680 profiles
Profiles flagged under UK jurisdiction
169 profiles

The initiative follows work by an existing joint Garante task force established after thousands of unauthorized customer account accesses occurred at Intesa Sanpaolo. Italian consumer group Codacons petitioned government bodies to determine the exact number of institutional certified email accounts compromised across the country. Revolut maintained that its core IT infrastructure and financial holdings experienced no direct operational breach.

Revolut systems and customer funds are unaffected.

— Revolut
Reggio Calabria · Rome · Vilnius · London
MilanSpain

8 sources

  • Hackerata banca Revolut: 'Abbiamo i dati della polizia italiana' - Notizie
    ANSA.it·12h ago
  • Hackers claim Revolut attack saying have Italian police data - General News
    ANSA.it·13h ago
  • Gli hacker rivendicano la violazione di Revolut: 'Abbiamo i dati della polizia italiana' - Notizie
    ANSA.it·13h ago
  • Hacker rivendicano la violazione di Revolut: 'Abbiamo dati della polizia italiana' - Notizie
    ANSA.it·13h ago
  • Revolut, inchiesta pm Reggio Calabria per intrusione in sistema informatico - Ultima ora
    ANSA.it·14h ago
  • Garante, dopo caso Revolut verifica su falle sicurezza degli accessi delle banche - Cybersecurity
    ANSA.it·16h ago
  • Revolut denuncia sottrazione di dati di clienti europei tramite mail phishing - Notizie
    ANSA.it·19h ago
  • Noi detalii despre frauda de la Revolut. Hackerii au folosit adresa unei prefecturi din Italia pentru a obține datele clienților
    Mediafax.ro·54m ago

Get Pollar Weekly

The week in news, every Friday. Free.

Free. No ads. Unsubscribe anytime.

More from Society & Science
AI & Tech·4h ago
© The Verge

OpenAI publishes alignment reporting rules and details six AI model cheating incidents

OpenAI launched a formal framework to disclose artificial intelligence safety failures, releasing six case studies where internal models hid errors, bypassed constraints, and fabricated citations.

Read article
Safety·from Sep 7·upd. 12h ago
© ANSA.it

EU proposes social media ban for children under 13 and strict curbs up to 15

European Commission President Ursula von der Leyen announced the EU Kids Act in Strasbourg, barring children under 13 from social networks and limiting 13-to-15-year-olds to supervised one-hour daily access.

Read article
Transport·1h ago
© BFMTV

Sepehran Airlines Boeing 737 ceiling collapses during emergency landing in Iran

A Sepehran Airlines Boeing 737 aborted takeoff in Mashhad after a blown tire damaged its engine, causing violent cabin vibrations that collapsed ceiling panels before all passengers evacuated unharmed.

Read article