Security1 publisher2 min readPublished
Fake police orders from a real Italian government mailbox got data on 680 Revolut customers
Revolut says its own systems were not breached; the fraudulent European Investigation Orders arrived from an authentic pec.interno.it mailbox, and the actor behind them claims six months inside Italian law-enforcement systems.
The Watch · Security desk

What happened
- Revolut confirmed its systems were not breached and that it acted on fraudulent requests that appeared to originate from a legitimate Italian government domain.
- The Financial Times reported that approximately 680 Revolut customers were affected by the exposure.
- The information reportedly obtained included identity documents, addresses, banking information, account statements, verification selfies and transaction histories, including cryptocurrency transactions.
- The threat actor IAmNotAVillain claims responsibility and alleges it held access for about six months to systems belonging to several Italian law-enforcement departments.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Any institution that answers European Investigation Orders authenticates the sender by domain and mailbox, so a single captured government account reaches customer files across every firm that honours the channel.
- capability Feeding transaction IDs and deposit addresses into a legal-request pipeline turns the process into a deanonymisation service: on-chain identifiers come back attached to names, addresses and selfies.
- contradiction The confirmed facts point at a mailbox takeover and Revolut's release decision; the unverified 147 GB claim would point at Italian institutional networks, and the two readings imply different remediation owners.
- decision Italian investigators now choose between examining one prefecture account and auditing PEC authentication records across other public administration mailboxes, including the one copied on the message.
PEC is Italy's certified email system, and it authenticates the mailbox. The person at the keyboard sits outside what it checks. According to Security Affairs, the request to Revolut came from an account on the pec.interno.it domain allegedly tied to the Prefecture of Reggio Calabria [2]. The senders posed as officers of the Italian Postal Police [3]. A recipient checking the domain and the institutional sender address finds nothing wrong. The forgery sat in the paperwork: European Investigation Orders that Security Affairs describes as fraudulent [8].
The asks were specific. The attackers sent transaction identifiers and blockchain deposit addresses and asked Revolut to link them to individual customers [6]. Researcher Korra of Duel described the operation as a form of "spray and pray" [7], submitting large numbers of transaction IDs and deposit addresses believed to be associated with high-value Revolut accounts [8].
The step that failed turns an inbound legal request into a release decision. With a genuine header on a fraudulent order, the only check left is a callback to the issuing office on a number the recipient sources itself.
The message to Revolut allegedly carried a second institutional PEC address in copy [13]. Traffic from one government mailbox to another looks like ordinary correspondence between offices [14]. Whether that second mailbox was also compromised, or was simply used to make the request look routine, is open, and settling it takes the original email headers, PEC logs and authentication records [15].
Hold the larger claim separately. IAmNotAVillain says it exfiltrated roughly 147 GB, including internal documents, emails, calendars and personal information [10], and that has not been independently verified [11]. The researcher @sonoclaudio, who supported the Security Affairs investigation, separated the two readings: one compromised PEC mailbox gives attackers a powerful impersonation tool, while 147 GB pulled from institutional systems would indicate a much broader compromise of government infrastructure [12].
Security Affairs does not date the fraudulent requests or the claimed intrusion [17]. Investigators still have to establish where the alleged dataset came from, which systems were accessed, when the compromise happened and what was taken [16].
What to watch
- PEC logs and authentication records for the Reggio Calabria mailbox. Those records would show whether the account was taken over or the messages were spoofed elsewhere.
- Whether any part of the claimed 147 GB is published or matched to a named Italian law-enforcement department.
- Whether banks and exchanges start requiring out-of-band callbacks before answering a European Investigation Order.