
Hackers obtain data on 680 Revolut customers using compromised Italian government email
Italian prosecutors and British regulators opened investigations after cybercriminals used a certified email account belonging to the Reggio Calabria Prefecture to obtain sensitive customer records from digital bank Revolut.
Deceptive requests and internal handovers
Cybercriminals operating under the moniker "iamnotavillain" obtained sensitive data belonging to 680 Revolut customers across several European countries by impersonating Italian law enforcement personnel. Over several months, the perpetrators transmitted fraudulent records requests through a certified electronic mail (PEC) address registered to the Reggio Calabria Prefecture. The requests were delivered to Revolut's Lithuanian banking entity rather than its Italian office, citing fabricated criminal proceedings linked to the Milan Prosecutor's Office and referencing European Investigation Orders.
Correspondence between the perpetrators and Revolut revealed several structural discrepancies in the requests. The fraudulent filings paired a southern Italian prefecture address with a Milan judicial inquiry and displayed incorrect protocol numbers tied to the Rome Prosecutor's Office. On 24 March 2026, Revolut compliance staff instructed the scammers to adjust their document headers to satisfy standard processing requirements. Following delays in May 2026 attributed to an internal review, Revolut confirmed on 24 July 2026 that it had transmitted the files, with decryption keys supplied separately. Transferred materials included passports, national identity cards, verified photographs, home addresses, bank account details, and Bitcoin transaction records. Revolut noted during processing that 169 requested accounts belonged to United Kingdom jurisdiction, requiring separate judicial requests.
- Revolut compliance staff ask scammers to reformat request headers
- Revolut notes document delivery delays due to an internal audit
- Revolut confirms transfer of requested customer data files
- Italian prosecutors and British regulators open data breach inquiries
Regulatory and judicial investigations
The Public Prosecutor's Office of Reggio Calabria opened a criminal inquiry under Article 615 ter, paragraph 3, of the Italian penal code, covering unauthorized access to public-interest computer systems. Postal Police investigators are examining whether the certified email account was infiltrated directly or cloned by the attackers. Italian authorities noted that investigators possess no confirmation that physical computers at the prefecture or the Viminale headquarters of the Ministry of the Interior were compromised.
The National Anti-Mafia and Counter-Terrorism Directorate stepped in to oversee the case under protocols activated when government bodies face digital intrusions. The hacker collective contacted the Financial Times via Telegram and shared email screenshots, claiming to hold 147 gigabytes of internal Italian police data, agency chats, and administrative documents. The group demanded a financial ransom from Revolut under threats of publishing customer records, prompting dark web monitoring by European law enforcement. In the United Kingdom, the Information Commissioner's Office launched a formal investigation after Revolut reported itself to British authorities.
Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators.
Systemic vulnerabilities and banking safeguards
Italian privacy authority Garante launched an inspection of access protocols across domestic financial institutions to identify potential system vulnerabilities. The regulator sent formal advisories to bank data protection officers, requesting immediate internal audits and rapid escalation of any detected breaches. The agency also coordinated with Lithuanian privacy regulators overseeing Revolut's primary European license and engaged the Ministry of the Interior to evaluate weaknesses in official PEC infrastructure.
- Total customer profiles transferred
- 680 profiles
- Profiles flagged under UK jurisdiction
- 169 profiles
The initiative follows work by an existing joint Garante task force established after thousands of unauthorized customer account accesses occurred at Intesa Sanpaolo. Italian consumer group Codacons petitioned government bodies to determine the exact number of institutional certified email accounts compromised across the country. Revolut maintained that its core IT infrastructure and financial holdings experienced no direct operational breach.
Revolut systems and customer funds are unaffected.


