Sep 17
/
Latest News
Hackers Say Revolut Breach Targeted 680 High‑Value Crypto Whales Using Compromised Italian Government Email System
Hackers claiming responsibility for the recent Revolut data breach say they specifically targeted 680 high‑net‑worth crypto users, obtaining their personal information by compromising an Italian government email system and posing as law enforcement for several months.
In messages shared with the Financial Times, the group said it gained access to confidential customer data by infiltrating Italy's La Posta Elettronica Certificata (PEC) system, a government‑run secure email network used for official and legal correspondence. The attackers then exchanged messages with Revolut while impersonating an arm of Italy's interior ministry.
The hackers said they repeatedly requested customer information for specific individuals, claiming the data was needed for ongoing investigations. The requests allegedly included addresses, phone numbers, and detailed transaction histories. Messages shared with the FT appeared to show Revolut responding to the PEC account and providing customer information under the assumption it was communicating with legitimate authorities.
Revolut may have been particularly vulnerable to the impersonation scheme. The company was fined EUR 11.5 million the previous year by Italy's competition authority for misleading information related to investment services, a regulatory history that may have made the firm more cautious about refusing official‑looking requests.
The hackers told the FT that the 680 targeted customers were selected using blockchain analysis to identify Revolut accounts with significant crypto holdings. Most of the affected users were based in Switzerland and France, but Revolut also disclosed data belonging to residents of 31 other countries, including the United Kingdom, Germany, and Spain.
The group has launched a Website and begun posting redacted screenshots of the information allegedly obtained from Revolut. They claim they are prepared to release additional data unless the company pays a ransom. Revolut, however, insists it has not been contacted by the perpetrators and has not received any ransom demand.
The breach adds to Revolut's growing list of security challenges and comes shortly after the company confirmed a separate incident in which fraudsters used a legitimate government email domain to request customer records. The latest claims highlight how attackers increasingly exploit trusted government communication channels to bypass corporate security controls.
In messages shared with the Financial Times, the group said it gained access to confidential customer data by infiltrating Italy's La Posta Elettronica Certificata (PEC) system, a government‑run secure email network used for official and legal correspondence. The attackers then exchanged messages with Revolut while impersonating an arm of Italy's interior ministry.
The hackers said they repeatedly requested customer information for specific individuals, claiming the data was needed for ongoing investigations. The requests allegedly included addresses, phone numbers, and detailed transaction histories. Messages shared with the FT appeared to show Revolut responding to the PEC account and providing customer information under the assumption it was communicating with legitimate authorities.
Revolut may have been particularly vulnerable to the impersonation scheme. The company was fined EUR 11.5 million the previous year by Italy's competition authority for misleading information related to investment services, a regulatory history that may have made the firm more cautious about refusing official‑looking requests.
The hackers told the FT that the 680 targeted customers were selected using blockchain analysis to identify Revolut accounts with significant crypto holdings. Most of the affected users were based in Switzerland and France, but Revolut also disclosed data belonging to residents of 31 other countries, including the United Kingdom, Germany, and Spain.
The group has launched a Website and begun posting redacted screenshots of the information allegedly obtained from Revolut. They claim they are prepared to release additional data unless the company pays a ransom. Revolut, however, insists it has not been contacted by the perpetrators and has not received any ransom demand.
The breach adds to Revolut's growing list of security challenges and comes shortly after the company confirmed a separate incident in which fraudsters used a legitimate government email domain to request customer records. The latest claims highlight how attackers increasingly exploit trusted government communication channels to bypass corporate security controls.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.