A suspected compromise of an Italian government PEC email account may have enabled attackers to impersonate law-enforcement officials and obtain sensitive information on about 680 Revolut customers, according to the Financial Times. Revolut said its own systems were not breached, but that it received fraudulent requests appearing to come from the legitimate `pec.interno.it` domain. The account was reportedly linked to the Prefecture of Reggio Calabria, and the attackers allegedly posed as Italian Postal Police officers.
The information reportedly included identity documents, addresses, banking details, account statements, verification selfies and transaction histories, including cryptocurrency activity. Researcher Korra of Duel said the attackers used a “spray and pray” approach, submitting hundreds of transaction identifiers and blockchain addresses—particularly those believed to relate to high-value accounts—and using fraudulent European Investigation Orders to request associated customer data.
The incident highlights how a genuine government mailbox can be abused to create a credible identity, even when the email itself passes technical authenticity checks.
The attackers, identified as IAmNotAVillain, also claim to have retained access for about six months to several Italian law-enforcement departments and stolen roughly 147 GB of data, including emails, documents and personal information. That claim has not been independently verified. Investigators still need to establish how the PEC accounts were compromised, whether multi-factor authentication was enabled, and whether credentials, session tokens or other authentication material were stolen.
They are also examining a second government mailbox copied into the fraudulent correspondence, using email headers, PEC logs and authentication records to determine whether it was compromised or merely used to make the requests appear legitimate.