It rode Italy’s real certified-email system for months — no money moved, a $3M ransom is public
real gov mailbox ▸
months of requests ▸
680 ID sets out
Everything you need, on one screen
| question | short answer |
|---|---|
| Was Revolut hacked? | No. Nobody cracked its servers — it believed a fake request sent from a real government address |
| Who is hit? | Around 680 European customers |
| Is the money gone? | No. Revolut says no customer funds were touched |
| What did they take? | Passport details, driving licences, ID photographs, emails, phone numbers, some financial data |
| What happens now? | A public $3m ransom, authorities investigating — and targeted calls if you are one of the 680 |
Untouched: balances and transfers
In criminal hands: the documents that prove you are you
⚡ If you are one of the 680
Why this beats a leaked password for them. A card is cancelled in one phone call. An ID set is not — it feeds a fake verification, a loan in your name, or a call that already knows your birth date.
What to expect. Approaches quoting details only your bank should hold. Nothing legitimate arrives as a link you must click to “secure your account”.
🏛️ How the attack actually worked
The requests came through Italy’s PEC system — certified email that carries the legal weight of registered mail — from a Prefecture of Reggio Calabria mailbox on the Interior Ministry domain.
Investigators still cannot say whether that mailbox was infiltrated or cloned. Either way, the exchanges ran for months, not hours — long enough to look routine.
💰 The ransom, the claimants, the investigators
iamnotavillain posted a public demand for 6,000 Monero — about $3m, claims 147 GB and threatens to sell. Revolut says nobody contacted it directly; an earlier competing 10,000-Bitcoin demand was dropped.
Reggio Calabria prosecutors opened an investigation into intrusion into an IT system of public interest, the anti-mafia directorate is on it, and Italy’s privacy watchdog has looped in Lithuania, where Revolut is licensed.
🧠 The part worth keeping, plus every source
The weak point was trust, not a firewall: any company that treats “it came from an official address” as proof of identity is one mailbox away from this — and we were impersonated is not the same sentence as we were breached.
Euronews · OCCRP · Guardian · Bloomberg · SecurityWeek · Security Affairs
A password can be reset. A passport scan cannot.
!