Ethical Hacking News
A recent data leak incident involving Revolut customers has shed light on a more sinister issue - the alleged compromise of Italian government accounts, which may have enabled threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers. The incident raises important questions about identity security and the trust associated with official government communications. With approximately 680 Revolut customers affected, the attackers obtained sensitive information such as identity documents, addresses, banking information, and transaction histories, including cryptocurrency transactions. The incident highlights the need for organizations to evaluate requests involving large amounts of sensitive customer information against additional signals to ensure robust identity security measures.
The Italian government accounts compromise may have enabled threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers. The attackers allegedly posed as Italian Postal Police officers to establish their identity after compromising the government account. Approximately 680 Revolut customers were affected, with attackers obtaining sensitive information such as identity documents and banking information. The attackers used a "spray and pray" strategy, sending hundreds of cryptocurrency transaction IDs and requesting associated account details from Revolut. The incident highlights the need for organizations to evaluate requests involving large amounts of sensitive customer information against additional signals, including the authority of the requester. The compromise of the government account is a reminder of the importance of robust identity security measures and the need for organizations to stay vigilant in the face of emerging threats.
The recent data leak incident involving Revolut customers has shed light on a more sinister issue - the alleged compromise of Italian government accounts, which may have enabled threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers. The incident, which has been linked to a compromised Italian government PEC account, has raised important questions about identity security and the trust associated with official government communications.
According to reports, the attackers allegedly abused an authentic institutional communication channel to obtain sensitive information on Revolut customers. The compromised account was allegedly associated with the Prefecture of Reggio Calabria and used the pec.interno.it domain. The attackers posed as Italian Postal Police officers, which suggests that the compromise of the government account was used to establish the attackers' identity.
The incident has affected approximately 680 Revolut customers, with the attackers obtaining sensitive information such as identity documents, addresses, banking information, account statements, verification selfies, and transaction histories, including cryptocurrency transactions. The attackers allegedly sent Revolut transaction identifiers and blockchain deposit addresses and requested information linking those transactions to specific customers.
The operation appears to have relied heavily on the trust associated with official government communications. The attackers used a "spray and pray" strategy, sending hundreds of cryptocurrency transaction IDs to Revolut and asking for the associated account details. Revolut complied, which explains the sheer volume of data the hackers were able to obtain.
The incident highlights a fundamental problem in identity security. An email can be technically authentic and still be fraudulent in a broader sense. If an attacker controls a legitimate government mailbox, the message may pass technical checks designed to establish its origin. However, those controls do not necessarily establish that the individual operating the account is authorized to issue the request.
This distinction between authentication, identity, and authorization is critical. For organizations such as financial institutions, verifying the domain or email infrastructure of a government requester may no longer be sufficient. Requests involving large amounts of sensitive customer information should also be evaluated against additional signals, including the authority of the requester, the legal basis of the request, the scope of the information requested, and unusual behavioral patterns.
The alleged 147 GB dataset, which is claimed to have been exfiltrated from Italian institutional systems, raises further concerns. If confirmed, the central issue would no longer be limited to the exposure of Revolut customers. Investigators would need to determine whether sensitive Italian government information was stolen before the Revolut operation, during it, or as part of a much broader intrusion.
The attackers may not have needed to breach Revolut. They allegedly compromised the trust surrounding an official government identity, and used that trust as the access mechanism to sensitive financial information. That is what makes this case particularly significant.
The most important investigation may therefore not be inside Revolut. It may be inside the Italian government systems whose identity was allegedly abused. The incident demonstrates how a compromise inside one trusted organization can be leveraged to attack another without directly exploiting its infrastructure.
In conclusion, the Italian government accounts compromise and the Revolut data leak raise important questions about identity security and the trust associated with official government communications. The incident highlights the need for organizations to evaluate requests involving large amounts of sensitive customer information against additional signals, including the authority of the requester, the legal basis of the request, the scope of the information requested, and unusual behavioral patterns.
The alleged compromise of Italian government accounts and the Revolut data leak incident serve as a reminder of the importance of robust identity security measures and the need for organizations to stay vigilant in the face of emerging threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Italian-Government-Accounts-Compromised-Revolut-Data-Leak-Raises-Concerns-About-Identity-Security-ehn.shtml
https://securityaffairs.com/199180/data-breach/revolut-data-leak-may-trace-back-to-compromised-italian-government-accounts.html
Published: Wed Sep 16 09:48:04 2026 by llama3.2 3B Q4_K_M