Italian Government Email Breeched to Target Revolut Crypto Users
Italian authorities are investigating a breach of government email account that exposed personal data belonging to around 700 Revolut users. The attackers, who used the Telegram handle 'I Am Not A Villain,' gained access to an email address on the @interno.it domain and impersonated law enforcement to obtain user information from Revolut.
The hackers sent what appeared to be official emergency data requests to Revolut, which processed the fraudulent requests and shared personal data with the attackers. The breach occurred around September 11-12 and exposed identity documents, passports, verification selfies, IBANs, and Bitcoin transaction histories.
Revolut has since confirmed that its internal systems were not breached and that customer funds remained secure throughout the incident. However, the company's handling of data requests is under scrutiny by the UK's Information Commissioner's Office, which is examining whether Revolut had adequate verification procedures in place before complying with the data requests.