Un hacker attack led Revolut to deliver the personal and financial data di about 700 customers to a group of cybercriminals. The attackers, however, did not directly violate the fintech's systems: according to reconstructions, they used a real certified email address of the Italian police force, which they would have been able to access, to send a request that appeared official.
Revolut confirmed the incident on September 12, calling it a sophisticated scam. The company did not disclose the exact number of customers involved, but Financial Times It speaks of 680 people. The fintech, which has over 80 million customers worldwide and more than 5 million in Italy, has assured that its systems were not compromised and that from the accounts no money was stolen.
What Revolut customer data has been exposed
The request would have led to the delivery of information Particularly sensitive data: names, addresses, phone numbers, and emails, copies of passports and driver's licenses, photographs, and selfies used to verify identity. The attackers also allegedly obtained IBANs, bank statements, transactions, withdrawals, and transaction history, including bitcoin.
Among the customers involved there is the Barcelona footballer Georges mikautadze, the Kazakh tennis player Alexander Shevchenko, Mark Karpeles, former CEO of Mt. Gox, and Marc ZellerKarpelès said he received the communication from Revolut at 5:25 a.m. on September 12, initially thinking it was another scam attempt. The case of the entrepreneur has also been reported. Felix Romer, who allegedly received extortion threats related to his stolen data before Revolut informed customers of the incident.
The company has blocked the address used for the request and has notified authorities, law enforcement, data protection authorities, and financial regulators.
How Hackers Tricked Revolut
The reconstruction of the attack revolves around the mailbox. The group calling itself IAmNotAVillain claims to have compromised, about six months ago, an account with the domain @pec.interno.it, traceable to the Ministry of the Interior.
From that mailbox, a request was sent to Revolut's Lithuanian headquarters to obtain information on customers as part of an alleged investigation by the Milan Public Prosecutor's OfficeThe communication also referred to the European Investigation Order, the instrument that allows judicial authorities in one European Union country to request evidence and information located in another state.
The request, therefore, was not only sent from a genuine institutional address, but also had an apparently legitimate motivation. According to reports, Revolut responded by providing the data without directly contacting law enforcement to verify the request. The Ministry of the Interior has not yet publicly confirmed the breach.
Hackers claim to have more Italian data
IAmNotAVillain also claims to have had access to Italian authorities' systems for months and to have collected over 87 files, amounting to approximately 147 gigabytes, including documents, emails, and personal information. The group claims to be in possession of other material and threatens to publish it if it fails payment of a ransom.
However, these are the attackers' claims and have not yet been independently verified. The alleged motive, linked to KYC procedures—the checks financial companies use to verify customer identities—has also been indicated by the same group.
Meanwhile the checks by the authoritiesTuesday, September 15th theBritish Information Commissioner's Office announced an investigation after Revolut's report. In Italy, the Action MP Giulia Pastorella He announced a question to ask how many other requests may have originated from the same certified email address and whether other companies were involved.
