Financial Times reported on September 15, 2026, that hackers claim to have breached an Italian government email system to pull off a months-long fraud campaign against Revolut, specifically targeting what the paper described as the fintech’s “crypto whales.” The report adds a new layer to a breach Revolut first confirmed on September 12: this was not a one-off phishing email that slipped through, but, according to the attacker’s own claims, a sustained infiltration of law enforcement mail infrastructure in Italy that ran for months before anyone caught it.

The UK’s Information Commissioner’s Office opened a formal investigation into the incident on September 14, one day before the FT’s report landed. Revolut says the intrusion never touched its core banking systems or customer funds. But the data that did go out the door, passport scans, IBANs, bank statements, and Bitcoin transaction histories, is now reportedly being leaked on a schedule, one customer dossier at a time, as leverage in an extortion attempt.

What the Financial Times Reported Today

The FT’s story, headlined “Hackers say they breached Italian state email to target Revolut ‘crypto whales’,” ties together two threads that had been reported separately over the prior three days. The first is Revolut’s own admission that it disclosed sensitive customer data to “an unauthorized third party” after receiving requests sent from what it believed was “the email address of a domain belonging to a legitimate government agency.” The second is a hacker’s public claim that the access used to send those requests came from a genuine compromise of Italian law enforcement mail infrastructure, not a spoofed lookalike domain.

Revolut, the London-based fintech that offers banking, payments, and crypto trading to customers across Europe, confirmed the data disclosure but has stopped short of calling it a hack of its own systems. The company has repeatedly framed the episode as external impersonation rather than an intrusion, a distinction that matters legally but means little to the customers whose identity documents are now circulating.

How the Fraudulent Requests Reached Revolut

The mechanism at the center of this story is a certified email address, known in Italy as a PEC (posta elettronica certificata), under the domain pec.interno.it. That domain belongs to Italy’s Interior Ministry, the Viminale. Reporting has tied the specific mailbox used in the scheme to the Prefettura di Reggio Calabria, one of the regional prefecture offices that routinely sends legitimate legal requests to banks and fintechs on behalf of Italian authorities.

Because PEC addresses carry legal weight in Italy, similar to a notarized letter, and because the domain itself authenticated correctly, Revolut’s compliance pipeline treated the requests as it would any lawful demand from a regulator or police unit. There was no fake domain to catch, no obvious spoofing red flag. Once Revolut identified the pattern, it blocked the mailbox and looped in the impersonated agency, along with law enforcement and financial regulators, according to the company’s own account.

From a Single Request to a Six-Month Campaign

What separates this story from the initial September 12 disclosure is scale and duration. Cybernews and IT-Connect both reported that a threat actor using the handle “IAmNotAVillain” has claimed the operation against Revolut ran for roughly six months before detection, not a single successful request. The same actor claims to hold 147 GB of material pulled from Italian law enforcement systems more broadly, well beyond the data Revolut itself handed over.

Cybersecurity outlet Infostealers reported that the intrusion traces back to roughly 300 compromised pec.interno.it webmail logins, credentials harvested from machines already infected with infostealer malware rather than a direct exploit of government servers. That detail matters for the market: it means the entry point was ordinary credential theft on infected endpoints, the same commodity infostealer economy that has fueled a wave of 2026 breaches, not a novel zero-day against Italian state infrastructure.

Why Revolut’s Crypto Customers Were the Target

The FT’s framing around “crypto whales” lines up with an assessment from blockchain investigator ZachXBT, who reviewed the leaked samples and concluded the operation appears to have selectively targeted high-net-worth Revolut users with meaningful crypto holdings rather than a random customer slice. That distinction shapes the risk profile considerably. A leaked passport scan is bad on its own, but paired with confirmed Bitcoin balances and transaction histories, it becomes a target list for SIM-swapping, physical extortion, or wrench-style attacks against people known to hold crypto.

Cryptotimes reported the confirmed victim count at 680 customers, with records skewing toward Switzerland and France. That figure is smaller than the 147 GB the attacker claims to hold from the broader Italian law enforcement compromise, which suggests the Revolut data is one slice of a larger haul rather than the entirety of what was taken.

Timeline: How the Revolut Incident Unfolded

DateEventSource
Roughly 5-6 months before September 2026First fraudulent request allegedly sent from a pec.interno.it mailboxCybernews, IT-Connect
September 11, 2026Revolut begins notifying affected customers by emailTechCrunch
September 12, 2026Revolut publicly confirms the data disclosure, calls it external impersonationTechCrunch, BleepingComputer
September 12-14, 2026Hacker “IAmNotAVillain” begins drip-feeding customer dossiers on TelegramCybernews, Pasquale Pillitteri
September 14, 2026UK Information Commissioner’s Office opens a formal investigationVerified fact sheet
September 15, 2026Financial Times reports the alleged Italian state email breach and “crypto whale” targetingFinancial Times

The Extortion Playbook: Drip-Feed Leaks and a Bitcoin Demand

Rather than dumping the entire dataset at once, the attacker has been releasing one customer dossier per day on Telegram, a pressure tactic that keeps the story alive in the press cycle and keeps individual victims in the dark about whether they are next. Cryptotimes reported a demand of 10,000 Bitcoin, an amount worth well into the billions of dollars at current market prices, though there is no public indication Revolut has engaged with the demand or that any payment has been made.

Drip-feed extortion has become a recognizable pattern in 2026 breach cases because it shifts leverage away from the victim company’s ability to simply absorb a single bad news cycle. Every day without a resolution produces a fresh headline and a fresh exposed customer, which is precisely what happened here: the story moved from a single-day TechCrunch confirmation on September 12 to a multi-outlet, government-implicating story by September 15.

UK Regulator Opens a Formal Investigation

The Information Commissioner’s Office’s decision to open an investigation on September 14 puts Revolut under formal UK data protection scrutiny, separate from whatever Italian authorities decide to do about the alleged compromise of their own mail systems. Under UK GDPR, a controller that discloses personal data to an unauthorized party, even one it was tricked into trusting, can face enforcement action if its verification controls are found inadequate. The ICO has not published findings, and any penalty, if one comes, is likely months away.

Italian authorities, for their part, have not confirmed a compromise of Interior Ministry systems. The Viminale is named in reporting as the owner of the pec.interno.it domain, and the Prefettura di Reggio Calabria has been identified as the office tied to the specific mailbox, but neither has issued a public statement matching the attacker’s six-month, 147 GB claim. Readers should treat the scale of the alleged Italian-side breach as an unconfirmed claim from the attacker until Italian authorities say otherwise.

Revolut’s Official Response and What It Disputes

Revolut has described the episode as a “sophisticated external impersonation scam,” language The Record and other outlets have noted it has repeated across multiple statements rather than characterizing it as a breach of its own infrastructure. The company maintains that no systems were compromised, no malware touched its environment, and no customer funds were accessed. It says it blocked the offending mailbox as soon as the pattern was identified and alerted the impersonated agency along with law enforcement, data protection, and financial regulators.

That framing puts the fault on a broken verification process rather than a technical failure, which is a meaningfully different story for regulators and insurers than a hacked database would be. Whether the ICO agrees that a five-to-six-month pattern of unchallenged requests from a single mailbox reflects adequate controls is likely to be the central question of its investigation.

How This Compares to Other 2026 Impersonation and Government-Domain Breaches

Revolut is not the only 2026 incident built on trust in an official-looking domain or login rather than a broken firewall. Comparing the mechanics side by side shows how consistent this failure mode has become across sectors.

IncidentAttack VectorScaleRegulatory Response
Revolut / Italian PEC email (Sept 2026)Compromised government email credentials, no spoofed domain680 confirmed customers; 147GB claimed from broader Italian systemsUK ICO investigation opened Sept 14, 2026
Florida DMV breachSingle compromised employee login~200,000 records exposedDisclosed within days; DPPA liability concerns raised
Veradigm vendor API breachThird-party vendor API exposureSSNs exposed; third breach in two years for the companyUnder review by affected state regulators
JetBrains Cadence breachUnpatched CVSS 9.8 vulnerabilityBug left open 16 days before fixVendor patched after disclosure

The pattern across all four is the same: the weakest point in 2026 breach cases keeps being trust in a credential, a login, or a domain, rather than a technical vulnerability in a hardened perimeter. Attackers have adjusted their economics accordingly, favoring identity abuse over exploit development because it is cheaper and harder to detect in real time.

Government Email Domains as an Overlooked Attack Surface

PEC systems like pec.interno.it exist because Italian law gives certified email the same legal standing as registered postal mail, which is exactly why a compromised mailbox on that domain is so valuable to an attacker. A request from a verified government domain skips the skepticism a company would normally apply to an unsolicited email, because the entire point of the system is to remove friction from lawful government-to-business communication.

That same design choice becomes a liability the moment credentials on that domain are stolen. Infostealer malware harvesting saved logins from infected machines is a commodity problem, cheap to run at scale and often undetected for months, which lines up with the six-month window reported in this case. Government agencies that rely on certified-email trust models are, in effect, extending their authentication guarantee to whatever email client and endpoint hygiene their staff happen to practice.

Historical Context: Social Engineering Has Outpaced Zero-Days in 2026

Security researchers have spent much of 2026 tracking a shift away from exploit-driven breaches toward credential and identity abuse, and this incident fits that trend cleanly. Rather than reverse-engineering a patch or buying a zero-day, attackers increasingly buy stolen credentials from infostealer logs, some sold for a few dollars per machine on dark web markets, and use them to walk through the front door.

The Revolut case also echoes a recurring theme in impersonation fraud against fintechs: companies build fast-lane processes for law enforcement requests because delaying a genuine investigation carries its own legal and reputational risk, and attackers exploit exactly that speed-over-scrutiny tradeoff. The same dynamic has shown up in breaches at other regulated financial platforms over the past two years, though rarely with a claimed government-mailbox compromise behind it.

Market and Reputational Impact for Revolut

Revolut has spent years building a reputation as a digital-first alternative to traditional banks, with identity verification as a core selling point of its onboarding process. A breach narrative in which that same verification muscle failed against a forged-but-authentic-looking government request cuts against that pitch directly. The company has not disclosed direct financial costs tied to the incident, and Blockonomi reported it has not confirmed engaging with the reported Bitcoin extortion demand.

The bigger near-term risk is regulatory rather than financial. An active ICO investigation, layered onto a drip-feed leak campaign still generating fresh headlines daily, gives Revolut little control over the news cycle. Every additional dossier the attacker releases on Telegram effectively resets the story for a new audience, which is a harder pattern for a communications team to manage than a single disclosure event.

What Crypto Holders and Fintech Customers Should Do Now

Revolut customers, particularly those with meaningful crypto holdings, should treat any unexpected contact referencing their account, balance, or identity documents with heightened suspicion in the weeks following this disclosure, since leaked data of this kind typically feeds follow-on phishing and SIM-swap attempts rather than being used once and discarded. Enabling hardware-based two-factor authentication, moving significant crypto holdings into self-custody where practical, and watching for unsolicited “verification” calls or messages are the standard, practical responses to this kind of exposure.

More broadly, this incident is a reminder that verifying a document’s legal source, a certified domain, a signed request, a government letterhead, is not the same as verifying that the account behind it has not been compromised. Companies handling high-value identity or financial data should treat government-linked requests as still requiring a secondary verification channel, not an automatic pass.

Predictions: Where This Investigation Goes Next

  • Expect Italian authorities to eventually issue a public statement on the Interior Ministry mailbox compromise, given the scale of the attacker’s claims and mounting international press attention.
  • The ICO investigation is likely to focus on whether Revolut’s verification process for law enforcement requests met UK GDPR standards, a process question rather than a systems-security one.
  • More customer dossiers are likely to surface on Telegram in the coming days if the extortion demand remains unmet, keeping the story active into late September.
  • Other fintechs are likely to quietly review their own legal-request intake processes in response, even without public acknowledgment, given how closely this mirrors prior impersonation-driven breaches.
  • Expect scrutiny of PEC and similar certified-email systems used across the EU, since the trust model that made this attack effective is not unique to Italy.

Frequently Asked Questions

Was Revolut itself hacked?

Revolut says its own systems, including core banking infrastructure and customer funds, were not breached. The company describes the incident as external impersonation: it processed fraudulent data requests that appeared to come from a legitimate government email domain.

What is pec.interno.it and why does it matter?

PEC (posta elettronica certificata) is Italy’s certified email system, which carries legal standing similar to registered mail. The pec.interno.it domain belongs to Italy’s Interior Ministry, and reporting has tied the specific mailbox used in this incident to the Prefettura di Reggio Calabria.

How many Revolut customers were affected?

Cryptotimes reported 680 confirmed affected customers, with records concentrated in Switzerland and France. The attacker separately claims to hold 147GB of material from the broader alleged Italian law enforcement compromise, a figure that has not been independently confirmed.

Is the Italian government confirming its systems were breached?

No. As of September 15, 2026, Italian authorities have not confirmed the attacker’s claim of a broad compromise of Interior Ministry mail systems. The scale of that claim currently rests on the attacker’s own statements.

What data was exposed?

Reporting describes identity documents, verification selfies, IBANs, bank statements, phone numbers, addresses, and crypto transaction histories among the data disclosed to the attacker.

Is the attacker demanding a ransom?

Cryptotimes reported a demand of 10,000 Bitcoin. There is no public confirmation that Revolut has engaged with or paid this demand.

What should affected customers do?

Enable hardware-based two-factor authentication, watch for unsolicited “verification” contact referencing account details, and treat any follow-up messages tied to this breach as potential phishing rather than legitimate outreach from Revolut.

Who is investigating the incident?

The UK’s Information Commissioner’s Office opened a formal investigation on September 14, 2026. Italian law enforcement and data protection authorities have also reportedly been notified, though no formal Italian investigation has been publicly confirmed.