Italian cybercrime authorities are investigating the fraudulent use of a government email account that led Revolut to disclose sensitive customer information. Attackers appear to have used a compromised Italian certified email account to impersonate law enforcement and obtain data from the digital bank, without directly breaching Revolut’s internal systems or customer funds.
According to an ANSA report on the Italian investigation, the Polizia Postale is investigating suspected unauthorized computer-system access and computer fraud. The fraudulent requests reportedly came from an institutional email account associated with an Italian prefecture, with subsequent reporting identifying the Prefecture of Reggio Calabria.
Compromised PEC Exposed Customer Data
The attackers exploited Italy’s Posta Elettronica Certificata, or PEC, system, which provides legally recognized certification of message delivery. A legitimate PEC account can still become dangerous if criminals obtain control of it, because certification does not establish that the person currently operating the mailbox is authorized to do so. CERT-AGID explicitly warns that PEC certifies delivery, not the security of message contents.
Revolut notified 680 affected customers, according to the Financial Times. The disclosed material included identity documents, home addresses, banking information and transaction histories, while separate reporting said cryptocurrency activity was among the financial records exposed. Revolut said its own systems and customer funds were not compromised and that it blocked the address after detecting the fraud.
The wider PEC ecosystem was already facing increased abuse before the Revolut incident. CERT-AGID had handled more than 650 events involving compromised or fraudulently registered PEC accounts between January and mid-June 2026, compared with 103 PEC-related malicious events identified throughout 2025.
UK and Italian Authorities Investigate
The breach has also triggered scrutiny outside Italy. The UK Information Commissioner’s Office has opened an investigation after Revolut reported the incident, adding a data-protection review to the Italian criminal inquiry. Revolut said it notified law enforcement, government authorities, data-protection bodies and financial regulators after discovering the fraudulent requests.
The case differs from conventional attacks that compromise a financial institution’s servers or wallets. The attackers instead exploited trust between an institution and what appeared to be a legitimate government communications channel, demonstrating how identity and authorization failures can expose sensitive financial data even when core banking infrastructure remains intact.
That distinction also separates the incident from infrastructure-focused attacks such as the recent cyberattack that disrupted Zeus Lightning Wallet services or disputes involving alleged customer-data exposure at Polymarket. For Revolut, the immediate issue is now how the fraudulent government requests passed its verification controls and whether the compromised PEC account was used against other organizations.
The investigation remains active, with authorities still examining the scope of the compromised government account and the attackers’ activity. The next material finding will be whether investigators identify additional fraudulent requests or institutions affected through the same PEC infrastructure, which would determine whether the Revolut disclosure was an isolated incident or part of a broader impersonation campaign.
