Revolut Data Breach Shows How Trusted Government Email Can Become a Hacker’s Master Key
Hackers allegedly exploited a compromised Italian government email account to impersonate law enforcement and obtain sensitive information about hundreds of Revolut customers, exposing a dangerous weakness in how financial institutions authenticate official data requests.
The attackers reportedly gained access to Italy’s certified email system, known as PEC, and used that trusted channel to request customer records from Revolut over several months.
According to the Financial Times, the campaign targeted roughly 680 customers, including wealthy cryptocurrency holders.
Revolut said its internal systems and customer funds were not compromised. The fintech described the incident as an external impersonation scam in which an unauthorized party submitted fraudulent information requests through a legitimate government agency domain.
That distinction matters technically, but offers little comfort to affected customers. The exposed records reportedly included contact information, identity documents, verification photographs, account statements, transaction histories and details about cryptocurrency activity. Such information could support identity theft, highly convincing phishing attacks or attempts to physically target known crypto investors.
Jeremy Leasher, forward deployed security architect at digital forensics company Binalyze, said the attackers allegedly weaponized institutional trust rather than directly penetrating Revolut’s infrastructure.
“The hackers claim to have breached Revolut using inherent authority – in this case an Italian government’s email system to simply ask for the data they wanted.”
The larger security failure may be how long the government account allegedly remained under attacker control. A months-long campaign should have produced evidence across authentication records, mailbox activity and transferred files.
“That doesn’t happen without evidence: there will have been logins, emails and files being sent and received, that should have set alarms ringing – but clearly didn’t,” Leasher said.
The Revolut breach highlights why an official email address can no longer serve as sufficient proof of identity. Banks, technology companies and government agencies need independent verification for sensitive requests, particularly when those requests involve passports, financial histories or cryptocurrency holdings. Callbacks through separately verified channels, phishing-resistant authentication and continuous mailbox monitoring can reduce the risk.
Affected customers should also prepare for follow-on fraud. Leasher recommends enabling strong multifactor authentication, favoring passkeys or hardware security keys over text messages, using unique passwords stored in a password manager and regularly reviewing active devices and account sessions.
The incident is a reminder that trusted infrastructure can become an attack tool. When criminals inherit the authority of a government account, even organizations with uncompromised networks can still be persuaded to surrender their most sensitive data.


