INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Revolut Data Leak May Trace Back to Compromised Italian Accounts

| 2026-09-16 13:09 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers, specifically approximately 680 individuals. The attackers allegedly abused an authentic institutional communication channel to obtain this information, posing as Italian Postal Police officers. This cyber operation appears to rely heavily on the trust associated with official government communications. The incident may be part of a broader cyber incident involving compromised Italian government infrastructure, and threat actor IAmNotAVillain claims responsibility for the operation, which allegedly maintained access for approximately six months to systems belonging to several law-enforcement departments, exfiltrating around 147 GB of data including internal documents and personal information.
Technical Mitigations AI-generated
• Block or hunt for European Investigation Orders (EIOs) with suspicious transaction IDs and deposit addresses. • Patch the <a href="/auth/login?next=/detail/iffmraABGvYhsJJTGoCv" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a> domain to prevent impersonation attacks, as it was allegedly used by attackers posing as Italian Postal Police officers. • Implement additional verification steps for PEC account requests from government domains, such as requiring a second institutional PEC address in copy.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

pe•••••.it
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
FIVE_EYES FIVE_EYES financefinance governmentgovernment
Incident Timeline
‎September 16, 2026
Threat actors allegedly compromised Italian government PEC accounts, impersonating law enforcement and obtaining sensitive data from hundreds of Revolut customers.
industry Government
tactic Data Leak
attribution Revolut Data Leak May Trace Back
data_breach 147 GB dataset
organisation PEC
organisation Revolut
organisation Financial Times
victims 680 Revolut customers
organisation Duel
organisation European Investigation Orders
organisation SecurityAffairs
Tactical Metrics
Metrics
victims
680
Revolut Customers
Metrics
data_breach
147
Gb Dataset
Intelligence Sources