
Cybercriminals compromised a government certified email address to steal sensitive data from 680 Revolut customers.
AI-generated summary
Financial institutions are legally obliged to provide data to authorities in the event of official investigations. Hackers exploited this protocol using a hacked government address.
The cyber police have started investigations for unauthorized access to the computer system and computer fraud. The hackers would have used an official certified mail address of the Italian police to request and obtain all the data: from residence to passport, up to current accounts and bank movements
The hackers who defrauded Revolut used a compromised institutional email belonging to an Italian institution. By doing so, hiding behind a legitimate government agency email domain, cybercriminals managed to gain access to the personal data of almost 700 customers of the UK banking services company. The cyber police have opened an investigation into unauthorized access to the computer system and computer fraud and are working to trace those responsible.
The data of 680 customers was stolen
Confirming "a sophisticated external impersonation scam, in which an unauthorized third party used an email address belonging to a legitimate domain of a government agency to submit fraudulent requests for information", was the British fintech itself, born as a startup for digital payments and now a direct competitor of the largest European banks. Cybercriminals, in essence, managed to ask for and obtain sensitive information that was disclosed to an unauthorized third party. This involves passport data, residential addresses but above all bank accounts and economic transactions carried out by customers: approximately 680 according to what was announced by the company. But, says a spokesperson, “Revolut systems and customer funds were untouched.”
Used certified address of the Italian police forces
Revolut said it acted immediately when it noticed the hack. "As soon as the fraud was identified - explained a company spokesperson - we immediately blocked the address and informed the relevant government agency, as well as law enforcement authorities, data protection authorities and financial supervisory authorities". Furthermore, he added, "the limited number of people involved were directly contacted to inform them of the incident and provide them with assistance". As explained by the company, the hackers did not need to hack the servers or overcome complex IT barriers: it was sufficient to use an official certified email address of the Italian law enforcement agencies that had previously been hacked to obtain all the desired data from the bank, pretending they were necessary for an international investigation.
Financial institutions required to provide data to law enforcement and government agencies
The criminals would have worked on the attack for many months, taking advantage of the obligation to which all financial institutions are subject to provide law enforcement and government bodies with all the information necessary for any investigations or official dossiers. As reiterated by the Revolut spokesperson, “requests from verified government domain addresses are processed as mandatory legal requests”. In this case, they added from the UK company, “as the requests contained valid technical authentication of the domain, they were met as standard legal compliance with the reasonable expectation that this was a genuine agency investigation.”

The Turin review court has ordered precautionary custody in prison for a man accused of sexual harassment of a thirteen-year-old, overturning the previous decision of the investigating judge which had only imposed the obligation to sign.

Hackers used a compromised Italian institutional email to trick Revolut into obtaining customer data. The Postal Police is investigating for computer fraud, while the company confirms the violation but assures that the funds have not been touched.

The judiciary is investigating the complaint presented by Natalia Potenza, Valter Lavitola's ex-partner, for alleged mistreatment. Lavitola has been in prison since August as the alleged instigator of the attack on Sigfrido Ranucci.
The Court of Review of Turin ordered the precautionary custody in prison for the 42-year-old accused of molesting a thirteen-year-old, accepting the appeal of the prosecutor's office after his initial release.
Cristina Stillitano was wounded in the arm by a shot probably fired with a compressed air weapon in Via della Giuliana, near the Vatican in Rome. The woman is hospitalized for the removal of the bullet. The police are investigating.

Thirteen young people between 18 and 20 were reported by the Palermo Maritime Border Police for a violent brawl on board a cruise ship sailing between Naples and Palermo.