ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Revolut Data Leak Traced to Compromised Italian Government PEC Mailbox as Threat Actor Demands $3M Ransom

highData breachexploited in the wildimportance 72
What's new: Initial merged summary: first consolidation of reports on the Revolut data leak, covering the compromised pec.interno.it attack vector, the ~680 affected customers, the $3 million ransom demand, the actor's unverified 147 GB claim, and Hudson Rock's finding of 300+ compromised government credentials.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Attackers used a compromised Italian government PEC mailbox to impersonate law enforcement and obtain personal data on ~680 Revolut customers over roughly five months; Revolut's systems were not breached, and threat actor 'IAmNotAVillain' is publicly…

Revolut confirmed that its own systems were not breached. Attackers instead abused a legitimate mailbox on the pec.interno.it domain tied to the Prefecture of Reggio Calabria — reportedly compromised via an infostealer — to send fraudulent European Investigation Orders posing as law-enforcement requests to Revolut Bank UAB in Lithuania. Researcher Korra of Duel described a 'spray and pray' operation that used hundreds of cryptocurrency transaction IDs. Roughly 680 high-profile customers, reportedly crypto whales, had identity documents/passports, addresses, phone numbers, banking information, verification selfies and crypto transaction histories exposed. Threat actor 'IAmNotAVillain' publicly demanded $3 million from Revolut, though Revolut says it received no direct demand. The actor also claims six months of access to Italian law-enforcement systems and 147 GB of data exfiltrated from Italy's Interior Ministry (pec.interno.it); this claim remains unverified and the matter is under police investigation, while SecurityWeek reports the fraudulent requests to Revolut ran for roughly five months. Hudson Rock says it knows of more than 300 compromised credentials tied to pec.interno.it, suggesting attackers relied on existing infostealer logs rather than fresh infections. Investigators need email headers and PEC logs, and a second PEC address included in copy may have boosted the fraudulent requests' credibility.

  • Revolut's systems were not breached; attackers abused a legitimate pec.interno.it government mailbox tied to the Prefecture of Reggio Calabria to pose as law enforcement.
  • Access relied on an infostealer-compromised government email account used to send fraudulent legal requests to Revolut Bank UAB in Lithuania.
  • Approximately 680 customers, reportedly high-profile crypto whales, had identity documents/passports, addresses, phone numbers, banking information, verification selfies and crypto transaction histories exposed.
  • The 'spray and pray' campaign used hundreds of cryptocurrency transaction IDs and forged European Investigation Orders (per researcher Korra of Duel).
  • Threat actor 'IAmNotAVillain' publicly demanded $3 million from Revolut, but Revolut says it received no direct demand.
  • The actor claims six months of access to Italian law-enforcement systems and 147 GB exfiltrated from Italy's Interior Ministry (pec.interno.it); this remains unverified and is under police investigation.
  • Sources differ on timing: SecurityWeek reports the fraudulent requests to Revolut ran for roughly five months, while the actor's claimed access to Italian systems was six months.
  • Hudson Rock knows of more than 300 compromised credentials tied to pec.interno.it, suggesting existing infostealer logs were used rather than fresh infections.

Coverage timeline

  1. · 2d ago
    Security Affairs· 55
    Revolut Data Leak May Trace Back to Compromised Italian Government Accounts

    Attackers using a compromised Italian government PEC account impersonated law enforcement to obtain data on ~680 Revolut customers.

  2. · 1d ago
    SecurityWeek· 72
    Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

    A threat actor demanding $3 million from Revolut says fake government legal requests yielded data of about 680 customers, mostly cryptocurrency whales.