Revolut hackers ‘breached Italian state email to target crypto whales’

The hacker group claiming to be behind the major data breach at Revolut have told the Financial Times they obtained the confidential customer information by posing as Italian law enforcement after gaining access to a government email system.

In a series of Telegram messages sent to the paper, the group said it exchanged emails with the digital bank for several months, repeatedly asking it to share confidential account details for individual customers including addresses, phone numbers and transaction histories for law enforcement purposes.

The claims, made by a hacker group under the pseudonym iamnotavillain, suggest the hack affecting nearly 700 Revolut accounts was more extensive than the breach first acknowledged by the FinTech, the FT reported.

The alleged hackers said: “Revolut was complying like a ‘good boy’.”

The FT contacted the hackers via the messaging app Telegram after they set up a website late Monday displaying redacted screenshots of information allegedly obtained from the bank. The group then shared further screenshots with the news group, including emails purportedly exchanged with Revolut whilst posing as Italian law enforcement.

The emails appear to have originated from a branch of Italy’s interior ministry via the government’s La Posta Elettronica Certificata (PEC) email system. A person familiar with the matter confirmed to the FT that the requests to Revolut did originate from Italy’s PEC system and that correspondence had continued for several months.

PEC, or certified email, is a system overseen by the Italian Government as a way for public bodies, companies and individuals to send emails with similar legal status to registered mail, intended to both prove the identity of the sender and confirm receipt by the recipient.

Iamnotavillian told the FT they did not target users randomly, instead choosing their 680 targets using blockchain analysis to identify Revolut accounts with large cryptocurrency holdings, described as “crypto whales”.

Most of the targets came from France and Switzerland, the hackers said, but Revolut also handed over information on residents from 31 other mainly European countries including the UK, Germany and Spain.

At present, the identity and motivations of the hackers are unclear. A person familiar with the matter told the FT that Revolut has not yet been contacted by the perpetrators and has yet to receive a ransom demand, a common reason for such data breaches.

A member of Italy’s chamber of deputies belonging to opposition party Azione, Giulia Pastorella, told the FT she had demanded immediate clarification from the interior ministry, calling the potential security breach of a ministry-level PEC account “alarming at an unimaginable level”.

Italy’s postal police, state police, interior ministry and cyber security agency declined to comment to the FT on the matter, though officials confirmed that investigations were under way.



Share Story:

Recent Stories


Creating value together: Strategic partnerships in the age of GCCs
As Global Capability Centres reshape the financial services landscape, one question stands out: how do leading banks balance in-house innovation with strategic partnerships to drive real transformation?

Data trust in the AI era: Building customer confidence through responsible banking
In the second episode of FStech’s three-part video podcast series sponsored by HCLTech, Sudip Lahiri, Executive Vice President & Head of Financial Services for Europe & UKI at HCLTech examines the critical relationship between data trust, transparency, and responsible AI implementation in financial services.

Banking's GenAI evolution: Beyond the hype, building the future
In the first episode of a three-part video podcast series sponsored by HCLTech, Sudip Lahiri, Executive Vice President & Head of Financial Services for Europe & UKI at HCLTech explores how financial institutions can navigate the transformative potential of Generative AI while building lasting foundations for innovation.

Beyond compliance: Building unshakeable operational resilience in financial services
In today's rapidly evolving financial landscape, operational resilience has become a critical focus for institutions worldwide. As regulatory requirements grow more complex and cyber threats, particularly ransomware, become increasingly sophisticated, financial services providers must adapt and strengthen their defences. The intersection of compliance, technology, and security presents both challenges and opportunities.