Revolut Breach Tied to Hacked Italian Police Systems
The Revolut data-leak saga has proven considerably wider than the initial account. A hacker under the pseudonym IAmNotAVillain claims that the attackers maintained access to the systems of several Italian law-enforcement divisions for about six months and used state infrastructure to request the confidential data of the fintech service’s clients. The claims surfaced in a report on how the Revolut breach was linked to Italian police systems.
What the Original Leak Covered
It had earlier come to light that the Revolut leak affected nearly 700 clients. The fraudsters obtained copies of passports and driving licenses, identity-verification photographs, home addresses, IBANs, bank statements, and transaction histories, including cryptocurrency dealings. Revolut found no signs of a breach of its own infrastructure: employees handed over the information in response to requests that arrived from a genuine government-agency domain and appeared legitimate.
New Claims of a Wider Compromise
The new assertions concern not the composition of the disclosed client data but the alleged scale of the compromise of state systems. According to IAmNotAVillain, the attackers gained access to several law-enforcement divisions at once and stole about 147 GB of information. The trove supposedly included internal documents, calendars, personal files, and official correspondence. There is as yet no independent confirmation of the archive’s size or the six-month access.
The claimed 147 GB does not pertain to the Revolut database. The hacker speaks of a separate trove stolen from Italian agencies. The compromised infrastructure, by IAmNotAVillain’s account, made it possible to send requests to Revolut in the name of law enforcement and receive client dossiers without directly penetrating the banking systems.
Italian Police Open an Investigation
The Italian Postal Police have opened an investigation into unlawful access to a computer system and computer fraud. The inquiry is examining the compromise of an institutional email address that, presumably, belonged to one of the Italian prefectures. Italian state broadcaster ANSA reported that the Postal Police are investigating the compromised certified email account.
The first requests aroused no suspicion at Revolut, so employees sent the information sought. The correspondence continued until the fintech service decided to further verify the approaches and contacted the government agency directly. Representatives of the institution reported that they had not sent the requests. After uncovering the fraud, Revolut blocked the address and notified the government agency, law enforcement, and data-protection and financial-supervision regulators.
Revolut’s Confirmation and the Victims
Revolut confirmed that the fraudulent approaches came from an address within a legitimate government-body domain. As Reuters reported on the confirmed breach, the company stresses that its banking systems and customers’ money were unharmed. No signs were found of the attackers accessing user accounts directly either.
IAmNotAVillain claims that clients from Switzerland and France predominate among the obtained records, yet the stolen information supposedly spans residents of dozens of countries in Europe and other regions. The hacker also claimed to hold the data of well-known individuals, including a professional footballer. The authenticity of the published victim list and the full scale of the compromise have not yet been independently confirmed.
The Central Question
The main question now concerns how deeply the attackers penetrated the infrastructure of Italian authorities. The investigation must establish whether only the institutional mailbox was compromised, or whether the attackers genuinely controlled several internal systems for months and used a trusted state channel to systematically obtain data from Revolut.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.