Revolut Data Leak Traced to Compromised Italian Government PEC Mailbox as Threat Actor Demands $3M Ransom
Attackers used a compromised Italian government PEC mailbox to impersonate law enforcement and obtain personal data on ~680 Revolut customers over roughly five months; Revolut's systems were not breached, and threat actor 'IAmNotAVillain' is publicly…
Revolut confirmed that its own systems were not breached. Attackers instead abused a legitimate mailbox on the pec.interno.it domain tied to the Prefecture of Reggio Calabria — reportedly compromised via an infostealer — to send fraudulent European Investigation Orders posing as law-enforcement requests to Revolut Bank UAB in Lithuania. Researcher Korra of Duel described a 'spray and pray' operation that used hundreds of cryptocurrency transaction IDs. Roughly 680 high-profile customers, reportedly crypto whales, had identity documents/passports, addresses, phone numbers, banking information, verification selfies and crypto transaction histories exposed. Threat actor 'IAmNotAVillain' publicly demanded $3 million from Revolut, though Revolut says it received no direct demand. The actor also claims six months of access to Italian law-enforcement systems and 147 GB of data exfiltrated from Italy's Interior Ministry (pec.interno.it); this claim remains unverified and the matter is under police investigation, while SecurityWeek reports the fraudulent requests to Revolut ran for roughly five months. Hudson Rock says it knows of more than 300 compromised credentials tied to pec.interno.it, suggesting attackers relied on existing infostealer logs rather than fresh infections. Investigators need email headers and PEC logs, and a second PEC address included in copy may have boosted the fraudulent requests' credibility.
- Revolut's systems were not breached; attackers abused a legitimate pec.interno.it government mailbox tied to the Prefecture of Reggio Calabria to pose as law enforcement.
- Access relied on an infostealer-compromised government email account used to send fraudulent legal requests to Revolut Bank UAB in Lithuania.
- Approximately 680 customers, reportedly high-profile crypto whales, had identity documents/passports, addresses, phone numbers, banking information, verification selfies and crypto transaction histories exposed.
- The 'spray and pray' campaign used hundreds of cryptocurrency transaction IDs and forged European Investigation Orders (per researcher Korra of Duel).
- Threat actor 'IAmNotAVillain' publicly demanded $3 million from Revolut, but Revolut says it received no direct demand.
- The actor claims six months of access to Italian law-enforcement systems and 147 GB exfiltrated from Italy's Interior Ministry (pec.interno.it); this remains unverified and is under police investigation.
- Sources differ on timing: SecurityWeek reports the fraudulent requests to Revolut ran for roughly five months, while the actor's claimed access to Italian systems was six months.
- Hudson Rock knows of more than 300 compromised credentials tied to pec.interno.it, suggesting existing infostealer logs were used rather than fresh infections.
Coverage timelineoldest first · each row is one article
- · 2d agoRevolut Data Leak May Trace Back to Compromised Italian Government Accounts
Security Affairs· 55
Attackers using a compromised Italian government PEC account impersonated law enforcement to obtain data on ~680 Revolut customers.
- · 1d agoRevolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
SecurityWeek· 72
A threat actor demanding $3 million from Revolut says fake government legal requests yielded data of about 680 customers, mostly cryptocurrency whales.