Italian Email Network Breach Exposes Revolut Accounts in 33 Countries

www.news4hackers.com-italian-email-network-breach-exposes-revolut-accounts-in-33-countries-italian-email-network-breach-exposes-revolut-accounts-in-33-countries

Official Italian Network Compromised to Access Revolut Accounts in 33 Countries

Overview of the Cyberattack

Cybercriminals targeted approximately 680 Revolut users by leveraging legitimate government credentials and official communication channels instead of directly infiltrating the financial institution’s internal systems. The attackers impersonated law enforcement agencies using an authentic address linked to Italy’s certified government network, engaging in prolonged correspondence with Revolut to obtain sensitive account information.

Targeted Individuals and Scope

The campaign primarily focused on individuals holding substantial cryptocurrency reserves, identified through prior blockchain analysis, with victims spanning 33 nations. The breach involved the exploitation of Italy’s Posta Elettronica Certificata (PEC), a secure digital communication system mandated for official exchanges between public entities, businesses, and citizens.

Exploitation of Secure Communication Channels

This infrastructure’s legal recognition for verified interactions allowed the attackers to bypass standard verification measures. Over multiple months, the perpetrators initiated requests for basic personal data, such as names, addresses, and phone numbers, before escalating to detailed financial records, including transaction histories, IBAN numbers, identity documents, and confidential financial logs.

Geographic Impact and Response

While the majority of affected accounts were linked to users in Switzerland and France, the scheme impacted individuals in 31 other jurisdictions. Revolut detected the fraudulent communications and blocked the originating address, notifying relevant authorities, regulatory bodies, and affected customers.

Classification of the Incident

The incident was classified as an unauthorized disclosure of private data to an external party rather than a direct system breach or fund theft. Despite the circulation of screenshots claiming to display stolen information, the full extent and authenticity of the data remain unconfirmed, and the perpetrators have not been publicly identified.

Expert Insights and Recommendations

Cybersecurity experts highlighted the vulnerability of traditional security measures against advanced identity deception tactics. Prof. Triveni Singh, a former IPS officer and cybercrime specialist, emphasized that organizations cannot solely rely on verified domains to validate data requests. He recommended implementing independent verification of requesting entities, confirming the authority of individual officers, and enforcing multi-layered checks before releasing sensitive consumer information.

Italian Authorities’ Investigation

Italian authorities are investigating how unauthorized actors accessed the certified government communication platform and issued deceptive legal requests. Ongoing inquiries aim to determine the number of compromised accounts, the types of documents exchanged, and whether the collected data has been repurposed for further criminal activities.

Risks for High-Value Investors

Analysts warned that combining real-world identities with verified cryptocurrency holdings and transaction records creates significant risks for high-value investors, exposing them to targeted social engineering, fraud, and identity theft.

“Organizations cannot solely rely on verified domains to validate data requests,” said Prof. Triveni Singh, a former IPS officer and cybercrime specialist.

Conclusion

The incident underscores the evolving threats posed by sophisticated cybercriminal tactics, particularly when leveraging trusted communication channels. It highlights the need for robust verification processes and heightened awareness among financial institutions and users to mitigate risks associated with identity-based fraud.



About Author

en_USEnglish