As reported by SecurityAffairs, the exposure of approximately 680 Revolut customers' sensitive data was not the result of a technical breach of Revolut's infrastructure. Instead, threat actors allegedly compromised an Italian government PEC (Posta Elettronica Certificata) account tied to the Prefecture of Reggio Calabria, then used that compromised institutional channel to impersonate Italian Postal Police and submit fraudulent European Investigation Orders. Revolut complied with the requests — because they appeared to come from a legitimate government domain.

Key Takeaway: As reported by SecurityAffairs, the exposure of approximately 680 Revolut customers' sensitive data was not the result of a technical breach of Revolut's infrastructure.

This incident is a landmark case in what Shield53 tracks as institutional authority abuse — and it should concern every financial services CISO, compliance leader, and government IT administrator simultaneously.

Why This Matters More Than a Standard Breach

Most data breaches involve exploiting a software vulnerability, stealing credentials, or deploying malware. This case is fundamentally different: the attackers weaponized the trust infrastructure itself. PEC is Italy's legally certified email system — messages sent through it carry presumed legal validity and authenticity. When a request arrives from a pec.interno.it domain, the recipient has strong institutional and legal incentives to treat it as genuine.

The attackers didn't need to defeat Revolut's security controls. They needed to defeat the Italian government's email security — and once they had that foothold, Revolut's own processes worked against its customers. This is the core problem: when your compliance and legal response workflows are built on the assumption that government communications are trustworthy by default, a single compromised mailbox becomes a master key.

The most dangerous supply chain isn't software — it's trust. When an institutional identity is compromised, every downstream recipient becomes an unwitting accomplice.

The Data Exposed Is a Target's Complete Profile

According to the report, the information handed over included identity documents, addresses, banking information, account statements, verification selfies, and full transaction histories — including cryptocurrency transactions. This is effectively a complete KYC dossier. For 680 individuals, this is not just a privacy violation; it is a direct enabler for:

The Data Exposed Is a Target's Complete Profile
Targeted phishing and social engineering using real account details
Identity theft with government-issued IDs and selfies in hand
Physical security risks for high-net-worth individuals whose addresses and balances are now known to threat actors
Crypto tracing evasion — attackers now know which transactions are already on law enforcement's radar

The researcher Korra of Duel described the operation as a "spray and pray" approach — sending hundreds of transaction IDs and blockchain deposit addresses believed linked to high-value Revolut accounts. This suggests the attackers had prior intelligence, possibly from blockchain analytics or prior breaches, and were using the fraudulent legal requests to connect on-chain activity to real-world identities.

Who Is at Risk Beyond Revolut

This is not a Revolut-specific problem. Any organization that routinely processes law enforcement data requests — banks, fintechs, telecoms, cloud providers, social media platforms — is exposed to the same attack pattern. The compromise of a single government email account can cascade across dozens of private sector recipients who all trust the same institutional sender.

Italian government infrastructure is the immediate concern, but the pattern generalizes. Every jurisdiction with a formal legal process for data requests has this trust dependency. If the sending side is compromised, the receiving side has no independent mechanism to detect the fraud.

Shield53 Recommendations

For Financial Institutions and Data Request Processors

  • Implement out-of-band verification for all data disclosure requests. Never act on a single email — even from a government domain. Call back to a known, pre-verified phone number for the issuing authority and confirm the request reference number verbally.
  • Create a formal verification protocol for European Investigation Orders and similar legal requests. This should include checking the request against the issuing authority's case management system where possible, and requiring a secondary confirmation channel.
  • Rate-limit and flag unusual request volumes. A sudden surge of data requests linked to cryptocurrency transactions from a single requesting office should trigger automated review — the "spray and pray" pattern is itself a detection signal.
  • Log and retain all metadata from data requests — sender domain, timestamp, request content, fulfillment details — to support post-incident forensics and customer notification.
  • Notify affected customers proactively with specific guidance on identity monitoring, especially if KYC documents and selfies were disclosed.

For Government IT and Communications Teams

  • Audit all PEC accounts for compromise indicators — especially those with law enforcement or judicial request authority. Look for anomalous login locations, mailbox forwarding rules, and sent items matching the reported pattern.
  • Enforce MFA on all institutional email accounts — PEC included. If phishing-resistant MFA (FIDO2) is not already deployed, this incident is the justification to prioritize it.
  • Monitor outbound traffic from government mail servers for spikes in external communications to financial institutions, which could indicate mailbox abuse.

For Affected Revolut Customers

  • Assume your identity documents and selfie verification are compromised — place fraud alerts with credit agencies.
  • Monitor cryptocurrency wallets associated with your Revolut account for any unusual activity.
  • Be on high alert for targeted phishing using your real account details — attackers now have enough information to craft highly convincing messages.

The broader lesson is uncomfortable but necessary: in the modern threat landscape, institutional identity is itself a vulnerable asset. Defenders must stop treating government-originated requests as trusted by default and start treating them with the same verification rigor applied to any other external input. Trust is not a security control — verification is.