Invest1 publisher3 min readPublished
Revolut's compliance queue answered fraudulent legal requests over Italy's certified email for months
An unauthorized third party used a genuine Italian government email domain to ask Revolut for customer files, the bank says. Revolut sent back passports, verification selfies and full transaction histories for about 680 people.
The Investor · Invest desk

What happened
- The Financial Times reported the requests reached Revolut through Italy's Posta Elettronica Certificata system, the state-regulated certified email service, and that the exchanges ran for months.
- About 680 customers were affected and none of them were in the United States, according to a person close to the company.
- A group calling itself IAmNotAVillain published a $3 million ransom demand on its own website Wednesday.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- decision Banks that must answer a European Investigation Order inside a deadline now have to decide whether to verify each order by callback. A callback slows the one process they are legally required to complete quickly.
- cost At roughly $4,400 per affected customer, the ransom is the cheapest number in this story; the recurring cost is a verification step on every government request, paid by legal operations staff.
- precedent With government mailboxes in more than 25 countries advertised for sale, per the FBI, the input to this attack is a purchase, so the next attempt does not require any new capability.
The hackers told Duel, a group that says it investigates cybercrime, that they settled on Revolut Bank UAB, the London-based company's Lithuanian subsidiary. Their reason: it is obliged to answer a European Investigation Order, the cross-border evidence demand that European Union member states can send one another [7][8][9].
Once inside the queue the work was clerical. A compliance desk is measured on closing lawful requests inside a deadline, and helping a requester fix a malformed order is the job. By the same account, the attackers once sent a document in the wrong form and Revolut's staff explained how to correct it instead of treating it as a reason for suspicion [10].
IAmNotAVillain's $3 million against about 680 affected customers is roughly $4,400 a head. That is the price for passports, driver's licences, the selfies customers took to open their accounts, account numbers, statements and full transaction histories including crypto activity [11][2]. The input side was cheap. Hudson Rock builds a database out of infostealer logs and sells companies access to what it finds. It says it already holds roughly 300 compromised logins for that Italian government domain, and that it is "highly unlikely" the attackers infected Italian government employees themselves, and more likely that they bought logs somebody else had already collected [12][13][14].
"Revolut recently identified a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information," a Revolut spokesperson told American Banker [15]. The company blocked the address on detection and alerted the agency, law enforcement, data protection authorities and financial regulators [16]. Revolut has not said how it detected the fraud [17].
Which control failed depends on that. If the bank found out because a customer complained or the attackers over-asked, then nobody was watching the queue. American Banker's point holds: every U.S. bank runs a legal and compliance function that answers subpoenas and government records requests, and it typically sits outside the security team's view entirely [18]. If a control caught it, the failure is narrower, and a callback procedure closes it. "Just as we don't grant someone access to a bank vault simply because they arrived in a marked police car," said Anu Liinev of Veriff, "legal data requests coming through certified channels must undergo zero-trust verification" [19]. Verification of that kind adds a step to a queue that is already run against statutory deadlines.
A third reading is that this is Italy's problem. A working login is all it takes to send mail through the Posta Elettronica Certificata system, and multifactor enforcement at the channel would close the route without any bank changing a process [6]. In my view that one is the weakest of the three. The FBI's November 2024 notification on fraudulent emergency data requests documented an illicit forum listing "High Quality .gov emails," including U.S. credentials, and a seller claiming to control government email accounts in more than 25 countries [20].
What to watch
- Whether Italy's certified-mail operator enforces multifactor authentication on the compromised PEC accounts, and whether other banks report requests from the same domain.
- Whether the data protection authorities and financial regulators Revolut alerted open a formal action against the bank over the disclosures.
- Whether IAmNotAVillain publishes the 680 customers' records once the $3 million demand goes unpaid.