Cybercriminals have targeted approximately 680 Revolut customers by exploiting legitimate government credentials and official email channels, rather than breaching the digital lender's internal technical systems. Posing as law enforcement authorities through an authentic address tied to Italy's certified government email network, the attackers engaged in communications with Revolut over several months to solicit confidential account records.
The operation focused primarily on individuals maintaining substantial cryptocurrency balances, identified through prior blockchain analysis, with customers across 33 nations affected.
Exploiting Certified Government Networks to Target Crypto Holders
The breach centred on blockchain surveillance used to isolate accounts holding significant digital asset reserves, often described in the industry as cryptocurrency whales. After singling out these specific profiles, the perpetrators used Italy's Posta Elettronica Certificata (PEC) system to contact the bank.
Because this certified network is legally recognised and specifically designed for secure, verified communications between public bodies, citizens, and businesses, the fraudulent requests carried an appearance of official legitimacy, which allowed them to circumvent routine verification protocols entirely.
Over an extended exchange, the attackers presented their inquiries as formal law enforcement investigations. Initial correspondence sought foundational personal records, including customer names, residential addresses, and telephone numbers. As these interactions progressed, the requests broadened to encompass complete transaction histories, IBAN records, identity documents, and sensitive financial logs. While a substantial share of the exposed accounts belonged to clients based in Switzerland and France, the requests involved account holders across 31 additional jurisdictions.
Security Protocols Challenged by Identity Deception
Revolut eventually identified the fraudulent correspondence and blocked the originating address, subsequently alerting government officials, regulatory watchdogs, and police agencies, alongside notifying the affected customers directly.
The incident has been characterised as an unauthorised disclosure of private records to an external party, rather than a direct infiltration of bank infrastructure or a theft of customer funds. Although the perpetrators have since circulated screenshots purporting to show the harvested data, the complete scope and authenticity of the leaked material remain unverified, and the individuals behind the scheme have not been publicly identified.
Cybercrime specialists observed that this episode underscores the vulnerability of technical safeguards against sophisticated identity-based deception. Former IPS officer and cybercrime expert Prof. Triveni Singh stated that institutions cannot rely entirely on verified email domains to validate data disclosures. He emphasised that financial organisations must implement independent confirmation of the requesting body, authenticate the authority of the specific officer making the request, and maintain multi-layered checks before releasing any protected consumer information.
Ongoing Cross-Border Inquiries
Inquiries in Italy are currently directed at establishing how unauthorised users obtained access to the certified state communication platform in the first place, and dispatched these deceptive legal requests from it. Detectives are reviewing the precise volume of accounts compromised, the categories of documentation transferred, and whether the gathered files have been deployed or traded for subsequent criminal acts.
Analysts warn that pairing real-world identities with verified crypto holdings and past transactional movements leaves high-value investors particularly exposed to targeted social engineering, fraudulent schemes, and identity theft, making this kind of data leak potentially far more dangerous than a conventional breach.
FAQs
Q1. How did the attackers gain access to Revolut customer data?
Rather than breaching Revolut's systems, attackers used Italy's certified government email network (PEC) to pose as law enforcement authorities and request confidential customer records over several months.
Q2. Who was specifically targeted in this operation?
The attackers used blockchain analysis to identify Revolut customers holding substantial cryptocurrency balances, with around 680 customers across 33 countries affected, particularly in Switzerland and France.
Q3. Was any money stolen from customer accounts?
No, the incident has been characterised as an unauthorised disclosure of private records rather than a theft of customer funds or direct infiltration of Revolut's banking infrastructure.