A trusted government channel becomes a cybersecurity vulnerability.
Rome, Italy.
Revolut is facing an extortion attempt after cybercriminals obtained sensitive information belonging to approximately 680 European customers by impersonating an Italian government authority. The attackers have publicly demanded $3 million, threatening to sell the stolen information to other criminal organizations if payment is not made within 24 hours. Italian prosecutors have opened an investigation into the incident, which reportedly involved fraudulent information requests submitted through an official email account associated with the Prefecture of Reggio Calabria. The digital banking company has confirmed that customer information was compromised but maintains that affected clients’ funds remain untouched.
The operation appears to have relied on institutional impersonation rather than a conventional intrusion into Revolut’s banking infrastructure. Investigators are examining whether the government email account was compromised or convincingly replicated, allowing attackers to submit requests that appeared to originate from a legitimate authority. According to the Financial Times, the group identifying itself as iamnotavillain claims to possess approximately 147 gigabytes of information, potentially including passports, driving licenses, photographs and other identity documents. The full extent of the compromised material has not been independently established.
The attackers published their ransom demand on a dark web platform, requesting payment in Monero, a cryptocurrency whose privacy features can complicate transaction tracing. The Financial Times reported receiving evidence presented by the group, including a recording showing what appeared to be a collection of stolen documents. Revolut, however, stated that the criminals had not directly contacted the company to demand payment. This distinction separates the public extortion campaign from any confirmed direct negotiation with the financial institution.
The investigation has expanded beyond the banking sector. Prosecutors in Reggio Calabria are working alongside Italy’s National Anti-Mafia and Counter-Terrorism Directorate to determine how the attackers obtained or replicated official communications. Italy’s data protection authority has also initiated inquiries into possible security failures and contacted its Lithuanian counterpart, reflecting Revolut’s regulatory presence in that country. Authorities have yet to establish whether additional government systems were affected.
For customers, the consequences extend beyond the immediate security of their bank balances. Identity documents, contact information and transaction histories can potentially facilitate impersonation, targeted phishing and other forms of financial fraud. Individuals whose records have been compromised may therefore face risks even when no unauthorized withdrawal has occurred. The distinction between stolen personal information and stolen money is particularly important when assessing the consequences of this incident.
The case exposes a vulnerability in the relationship between financial institutions and public authorities. Banks must respond to legitimate legal requests, but authentication failures can transform trusted communication channels into mechanisms for unauthorized data disclosure. Effective protection consequently depends not only on securing internal infrastructure but also on independently verifying external requests before releasing sensitive information.
The investigation remains active, and the attackers’ claims concerning the volume of stolen data have not been fully verified. What is established is that a fraudulent request mechanism resulted in the disclosure of customer information and triggered a multimillion-dollar extortion attempt. The incident demonstrates how institutional trust itself can become an attack surface when verification procedures fail.
Más allá de la noticia, el patrón. / Beyond the news, the pattern.