Revolut crypto breach: fake Italian government emails exposed 680 crypto whales
0
0

A wave of stolen identity documents, transaction histories and bitcoin records tied to some of Revolut’s wealthiest crypto customers has surfaced online, and the trail leads back to a compromised Italian government mailbox rather than any break-in at the fintech itself. The Revolut crypto breach exposed personal data from 680 high-net-worth accounts after hackers posing as law enforcement officials convinced the bank to hand over confidential customer files, according to reporting from the Financial Times and multiple outlets tracking the fallout since Revolut confirmed the incident on September 12.
Key takeaways
- Hackers say they obtained personal data from 680 high-net-worth crypto accounts at Revolut, selected through blockchain analysis of wallet activity.
- Most affected customers were based in Switzerland and France, with Revolut also releasing data on residents of 31 other mostly European countries, including the UK, Germany and Spain.
- The requests came through Italy’s certified PEC email system, reportedly from an account tied to the Prefecture of Reggio Calabria, which has denied sending them.
- Italy’s Polizia Postale and the UK’s Information Commissioner’s Office are both investigating; Revolut says its systems and customer funds were never compromised.
- Hackers have posted redacted screenshots on a leak site and are reportedly threatening further disclosures unless a ransom is paid; Revolut says it has received no such demand.
Targeted Data Breach of Revolut Crypto Whales
This was not a scattershot attack. The people behind the leak deliberately hunted for Revolut‘s richest crypto holders, then used a trusted government channel to extract their personal files. The result is one of the more unusual fintech security stories of the year: a breach that never touched Revolut’s own infrastructure, yet still pulled sensitive data on hundreds of wealthy clients.
Hackers Identify High-Value Accounts via Blockchain Analysis
The group told the Financial Times it picked its 680 targets by running blockchain analysis to spot Revolut accounts holding substantial crypto balances. That detail matters because it shows the attackers weren’t guessing. On-chain data, cross-referenced with account activity, gave them a shortlist of clients worth pursuing before they ever contacted the bank. Crypto investigator ZachXBT, who first publicized Revolut’s breach notification, described the incident as limited in scope but clearly aimed at high-net-worth users — a characterization that lines up with the hackers’ own account of how they chose their victims.
Scope and Geographic Distribution of Affected Customers
Geographically, the leak skews heavily toward two countries. The majority of the 680 impacted customers were based in Switzerland and France, though according to the hackers, Revolut also disclosed data belonging to residents of 31 other countries, mostly in Europe, including the UK, Germany and Spain. Revolut itself has said only that a limited number of customers were affected and that it contacted them directly, without confirming the full breakdown by country.
Method and Mechanism of Data Theft
The attackers didn’t hack Revolut’s databases. Instead, they exploited the trust financial firms place in official government correspondence, using a certified Italian email system to request records under the guise of a legal investigation.
Use of Italian Government’s PEC Secure Email System
Messages shared with the Financial Times appeared to show Revolut exchanging customer account information with an arm of Italy’s interior ministry through La Posta Elettronica Certificata, known as PEC — a government-overseen network that Italian authorities, companies and private citizens use for legally binding correspondence, functionally the digital equivalent of registered post. Italian news agency ANSA reported that Polizia Postale, the country’s cybercrime police, is now investigating suspected unauthorized access to a computer system and computer fraud tied to the case. Italian media reports identified the compromised account as belonging to the Prefecture of Reggio Calabria, which was later reported to have denied sending any requests to Revolut, leaving investigators to determine how the mailbox was accessed.
Italy’s cybersecurity agency, CERT-AGID, had already flagged the risk months earlier. In June, the agency said it had handled more than 650 incidents involving abused or illicitly created PEC accounts since the start of 2026 — a warning that, in hindsight, foreshadowed exactly the kind of exploit used against Revolut. PEC certifies that a message was sent and delivered, but it does not verify that the person controlling the mailbox is who they claim to be. This is why the breach matters well beyond one company: any institution that treats a PEC-certified request as automatically legitimate is vulnerable to the same trick.
Impersonation of Law Enforcement to Request Confidential Data
According to the hackers’ own account, they repeatedly asked Revolut to share confidential details — addresses, phone numbers and transaction histories — for specific customers, claiming the information was needed for ongoing law enforcement activities. According to Revolut’s own breach notification, the information it eventually sent included birth dates, postal and email addresses, phone numbers, and copies of identification documents such as passports and driving licences, with the bank noting that verification selfies, account statements and transaction histories may also have been compromised. ZachXBT added that IBANs, withdrawal records, occupations and bitcoin-related transaction history were also part of what leaked, details Revolut’s own notice did not spell out.
Revolut may have been especially exposed to this kind of scheme given its regulatory history. The company had been fined €11.5 million by the Italian competition authority in the prior year over misleading information about investment services — a fine unrelated to this breach but part of the broader scrutiny Revolut has faced from Italian regulators.
Aftermath and Responses
What happens next hinges on two unresolved threads: whether the hackers escalate their leak campaign, and what Italian and British investigators find about how a government mailbox ended up in the wrong hands.
Hackers’ Ransom Threat and Data Leak Website
The group behind the breach set up a website and began posting redacted screenshots of information allegedly pulled from Revolut. A Reddit post referenced by Help Net Security claimed the group is releasing data belonging to VIP clients, demanding payment and threatening to release additional private messages, client files and internal material unless paid. The posture is a familiar extortion playbook: release a partial sample, then dangle the threat of a fuller dump.
Revolut’s Position and Past Regulatory Fines
On one point Revolut has remained steadfast: according to the company, it has not been contacted by those responsible and has not received any ransom demand so far. A company spokesperson told Cointelegraph, “We reported this to the Italian authorities upon detection and will assist them as needed,” adding that the firm’s systems, databases and customer funds remained secure throughout. Revolut has declined to name the specific government agency whose email was allegedly compromised, citing the active police investigation and confidentiality obligations.
Britain’s Information Commissioner’s Office is also examining the breach, adding a data-protection angle to the criminal probe underway in Italy. For crypto holders specifically, the exposure carries an added edge: pairing identity documents and banking details with bitcoin transaction history can tie a real name to blockchain activity that would otherwise be hard to trace to a specific person, a link that heightens the stakes for the affected whales well beyond typical identity-theft concerns.
Whether this becomes a one-off scandal or a template other fraudsters copy will likely depend on how European regulators respond to the underlying weakness: a certified email system that guarantees delivery but not identity. Until banks and fintechs build in independent verification for government data requests, the same playbook that worked against Revolut remains available to anyone who can get inside a trusted mailbox.
FAQ
How did hackers identify the 680 crypto whale accounts at Revolut?
Hackers used blockchain analysis to select Revolut accounts with significant crypto holdings.
What method did hackers use to obtain confidential customer data from Revolut?
Hackers impersonated law enforcement and used Italy’s PEC secure email system to request confidential account details from Revolut.
What is the role of the PEC email system in the data breach?
PEC is an official secure email system in Italy that gives legal standing to messages, which was used by hackers to request data under the guise of government authority.
Has Revolut received any ransom demand related to the breach?
Revolut insists that it has not been contacted by the perpetrators and has yet to receive a ransom demand.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.
0
0
Securely connect the portfolio you’re using to start.





