INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Revolut Data Leak May Trace Back to Compromised Italian Accounts
| 2026-09-16 13:09 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers, specifically approximately 680 individuals. The attackers allegedly abused an authentic institutional communication channel to obtain this information, posing as Italian Postal Police officers. This cyber operation appears to rely heavily on the trust associated with official government communications. The incident may be part of a broader cyber incident involving compromised Italian government infrastructure, and threat actor IAmNotAVillain claims responsibility for the operation, which allegedly maintained access for approximately six months to systems belonging to several law-enforcement departments, exfiltrating around 147 GB of data including internal documents and personal information.
Technical Mitigations AI-generated
• Block or hunt for European Investigation Orders (EIOs) with suspicious transaction IDs and deposit addresses.
• Patch the <a href="/auth/login?next=/detail/iffmraABGvYhsJJTGoCv" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a> domain to prevent impersonation attacks, as it was allegedly used by attackers posing as Italian Postal Police officers.
• Implement additional verification steps for PEC account requests from government domains, such as requiring a second institutional PEC address in copy.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
pe•••••.it
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
FIVE_EYES
FIVE_EYES
financefinance
governmentgovernment
Incident Timeline
September 16, 2026
Threat actors allegedly compromised Italian government PEC accounts, impersonating law enforcement and obtaining sensitive data from hundreds of Revolut customers.
Click on any entity below to view its context and source!
industry
Government
Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
Pierluigi Paganini
September 16, 2026
tactic
Data Leak
Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
Pierluigi Paganini
September 16, 2026
attribution
Revolut Data Leak May Trace Back
Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
Pierluigi Paganini
September 16, 2026
data_breach
147 GB dataset
As researcher @sonoclaudio, who supported my investigation, noted, there is a major difference between compromising a single PEC mailbox and allegedly extracting 147 GB of information from Italian institutional systems.
But if the 147 GB dataset exists, its origin could fundamentally change the assessment of the incident.
The group further claims to have exfiltrated approximately 147 GB of data, allegedly including internal documents, emails, calendars and personal information.
The alleged 147 GB dataset should therefore not be presented as an established fact at this stage.
organisation
PEC
As researcher @sonoclaudio, who supported my investigation, noted, there is a major difference between compromising a single PEC mailbox and allegedly extracting 147 GB of information from Italian institutional systems.
organisation
Revolut
Revolut has confirmed that its systems were not breached.
organisation
Financial Times
The
Financial Times
reported that approximately 680 Revolut customers were affected.
victims
680 Revolut customers
The
Financial Times
reported that approximately 680 Revolut customers were affected.
organisation
Duel
Researcher Korra of Duel described the operation as a form of “
spray and pray
.”
organisation
European Investigation Orders
According to the analysis, the attackers submitted large numbers of transaction IDs and deposit addresses believed to be associated with high-value Revolut accounts and used fraudulent European Investigation Orders to request customer information.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Revolut)
Tactical Metrics
Metrics
victims
680
Revolut Customers
Click for context!
The
Financial Times
reported that approximately 680 Revolut customers were affected.
Metrics
data_breach
147
Gb Dataset
But if the 147 GB dataset exists, its origin could fundamentally change the assessment of the incident.
As researcher @sonoclaudio, who supported my investigation, noted, there is a major difference between compromising a single PEC mailbox and allegedly extracting 147 GB of information from Italian institutional systems.
The group further claims to have exfiltrated approximately 147 GB of data, allegedly including internal documents, emails, calendars and personal information.
The alleged 147 GB dataset should therefore not be presented as an established fact at this stage.
Intelligence Sources
Security Affairs
2026-09-16
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T10:35
Comprehensive Tactical Telemetry
Highly Correlated Entities
6x
organisation
Identified Entity
Revolut
entity
4x
attribution
Attributing Entity
Revolut Data Leak May Trace Back
authority
3x
tactic
Cyber Operation Type
Data Leak
tactic
2x
industry
Targeted Sector
Government
sector
2x
target region
Target Country
Italy
country
Contextual Telemetry
Context Block
4 METRICS
timeline
Temporal Reference
September 16, 2026
date
source region
Origin Country
Italy
country
victims
Revolut Customers
680
revolut customers
data breach
Gb Dataset
147
gb dataset
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.