Smartphone displaying the Revolut name on screen while resting on a wooden surface.
REGULATION

Italy Investigates Revolut Data Leak Email Breach

Image credit: Unsplash

Italy’s cybercrime police are investigating the compromise of a government email account allegedly used to obtain sensitive records on hundreds of Revolut customers by impersonating law enforcement.

The investigation covers suspected unauthorized access to a computer system and computer fraud. Revolut says fraudulent information requests came from an email address belonging to a legitimate government agency domain, while its own systems and customer funds were not breached.

Italian Police Trace Fraudulent Requests to Prefecture Email 

Italian investigators are examining how attackers gained control of the institutional email account used to send the requests.

ANSA reported that the messages appeared to originate from the institutional email of an Italian prefecture. Separate Italian reporting has identified the Prefecture of Reggio Calabria as the institution involved, though authorities have not publicly confirmed that attribution.

The requests were reportedly sent through Italy’s certified Posta Elettronica Certificata, or PEC, system, which is used for official communications with legal standing.

Revolut initially processed the requests because they appeared to come from a legitimate government channel. After repeated requests raised concerns, the company contacted the institution directly, which denied sending them.

About 680 Customers Reportedly Had Sensitive Records Exposed 

Revolut has confirmed that an unauthorized party obtained customer information through the fraudulent government requests.

Potentially exposed information included names, birth dates, addresses, phone numbers, email addresses, identity documents, verification selfies, IBANs, account statements and transaction histories.

Financial Times reporting has put the affected population at about 680 customers across more than 30 countries, with Switzerland and France among the largest groups. Revolut has publicly described the number influenced as limited without confirming the total.

Revolut Blocks Compromised Address as Italian Police Investigate 

Italian investigators are now working to determine how the institutional email was compromised and reconstruct how it was used to obtain Revolut customer records.

Revolut said it blocked the address after detecting the impersonation and notified the affected government agency, law enforcement, data protection authorities and financial regulators.

The company maintains that the incident was an external impersonation fraud rather than a breach of Revolut’s own systems and says customer funds were not impacted.

More For You

Explore More News