🪪 Revolut handed 680 customers' IDs to a fake government email

:identification_card: It rode Italy’s real certified-email system for months — no money moved, a $3M ransom is public

:classical_building: real gov mailbox ▸ :page_facing_up: months of requests ▸ :identification_card: 680 ID sets out

:high_voltage: Everything you need, on one screen

question short answer
Was Revolut hacked? No. Nobody cracked its servers — it believed a fake request sent from a real government address
Who is hit? Around 680 European customers
Is the money gone? No. Revolut says no customer funds were touched
What did they take? Passport details, driving licences, ID photographs, emails, phone numbers, some financial data
What happens now? A public $3m ransom, authorities investigating — and targeted calls if you are one of the 680

:green_circle: Untouched: balances and transfers
:red_circle: In criminal hands: the documents that prove you are you

⚡ If you are one of the 680

Why this beats a leaked password for them. A card is cancelled in one phone call. An ID set is not — it feeds a fake verification, a loan in your name, or a call that already knows your birth date.

What to expect. Approaches quoting details only your bank should hold. Nothing legitimate arrives as a link you must click to “secure your account”.

🏛️ How the attack actually worked

The requests came through Italy’s PEC system — certified email that carries the legal weight of registered mail — from a Prefecture of Reggio Calabria mailbox on the Interior Ministry domain.

Investigators still cannot say whether that mailbox was infiltrated or cloned. Either way, the exchanges ran for months, not hours — long enough to look routine.

💰 The ransom, the claimants, the investigators

iamnotavillain posted a public demand for 6,000 Monero — about $3m, claims 147 GB and threatens to sell. Revolut says nobody contacted it directly; an earlier competing 10,000-Bitcoin demand was dropped.

Reggio Calabria prosecutors opened an investigation into intrusion into an IT system of public interest, the anti-mafia directorate is on it, and Italy’s privacy watchdog has looped in Lithuania, where Revolut is licensed.

🧠 The part worth keeping, plus every source

The weak point was trust, not a firewall: any company that treats “it came from an official address” as proof of identity is one mailbox away from this — and we were impersonated is not the same sentence as we were breached.

Euronews · OCCRP · Guardian · Bloomberg · SecurityWeek · Security Affairs

A password can be reset. A passport scan cannot.