Hackers breach Italian state email to target Revolut crypto users

1 hour ago 21

Someone hijacked a legitimate Italian government email address, used it to impersonate law enforcement, and convinced Revolut to hand over personal data belonging to roughly 700 customers. The attackers then turned around and demanded 10,000 Bitcoin from their victims.

The breach, which occurred around September 11-12, exposed identity documents, passports, verification selfies, IBANs, and Bitcoin transaction histories.

How the scam worked

The attackers compromised an email account on the @interno.it domain, which belongs to Italy’s Ministry of Interior. With that credential in hand, they sent what appeared to be official emergency data requests to Revolut, the London-based fintech giant that serves millions of users across Europe.

Emergency data requests are a standard mechanism that law enforcement agencies use to obtain user information from tech companies without a court order, typically in cases involving imminent danger. The system relies heavily on trust: if the email looks right and comes from the right domain, companies often comply quickly.

Revolut processed the fraudulent requests and shared personal data from between 680 and 700 users before anyone realized something was off.

The company has since confirmed that its internal systems were not breached and that customer funds remained secure throughout the incident.

The extortion campaign

The hackers, operating under the Telegram handle “I Am Not A Villain,” began circulating samples of the compromised information online and launched an extortion campaign against the affected users.

Their asking price: 10,000 Bitcoin.

Investigations on multiple fronts

The fallout has triggered investigations across two countries. Italy’s Polizia Postale, the country’s cybercrime unit, is leading the criminal inquiry alongside the Agenzia per la Cybersicurezza Nazionale, Italy’s national cybersecurity agency. Their primary focus is determining how the @interno.it email account was compromised in the first place.

Across the Channel, the UK’s Information Commissioner’s Office is examining whether Revolut’s data handling practices were legally sound. The ICO’s interest centers on whether the company had adequate verification procedures before complying with the data requests, and whether its response met the standards required under data protection law.

Revolut has said it took immediate action once the breach was identified. The company blocked the compromised email account, notified relevant Italian authorities and data protection agencies, and contacted each affected user directly.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article