Thursday, September 17, 2026Thu, Sep 17
HomeTechHackers Impersonated Italian Police via PEC Email to Steal Revolut Data
Tech · National News

Hackers Impersonated Italian Police via PEC Email to Steal Revolut Data

Hackers impersonated Italian police via official PEC email to obtain data from 700 Revolut users. Learn how this fraud worked and how to protect yourself.

Hackers Impersonated Italian Police via PEC Email to Steal Revolut Data
Laptop with digital padlock symbolizing email security breach

The Revolut Hack That Exposed Italy’s Digital Blind Spot

Hackers impersonated the Reggio Calabria Prefecture using a certified Italian government PEC email to trick Revolut into handing over personal data of nearly 700 customers — a breach that didn’t steal funds, but shattered trust in one of Italy’s most trusted digital tools. What followed wasn’t just a cyberattack; it was a systemic failure of how institutions signal legitimacy — and how financial platforms blindly believe what looks official.

Why This Matters

700+ Revolut users had passports, bank statements, and Bitcoin histories exposed after hackers impersonated the Reggio Calabria Prefecture

The breach exploited PEC, Italy’s legally binding email system — which verifies delivery, not identity

Italy’s cyber agency recorded over 650 PEC abuses since January 2026, with 80% targeting public administration

No government system was breached — but the fraud succeeded because the attack didn’t need to break in

How a Simple Email Trick Cost People Their Privacy

The attackers never hacked Revolut’s servers. They didn’t crack databases. They didn’t need to.

Instead, they sent a perfectly formatted, legally certified email from an official Italian government domain: . It bore the correct logos, proper formatting, even reference numbers matching internal police protocols. Revolut, trained to treat PEC messages as legally binding under Italian civil code, complied.

The request asked for KYC documents, transaction logs, and behavioral data on accounts with cryptocurrency activity. The hackers had spent months identifying high-value users via blockchain scans — a quiet, patient reconnaissance before striking.

When Revolut detected anomalies and blocked the address, the damage was done. The bank reported the incident to the UK Information Commissioner’s Office and Italian authorities. But by then, the data was already out — and the question shifted: How many institutions could this have worked on?

Why PEC Isn’t What You Think

Posta Elettronica Certificata is more than just Italian email. It’s a legal instrument. Courts accept PEC correspondence as proof of receipt with the same weight as a registered letter. Businesses rely on it for contracts, tax filings, and public notices.

But here’s the critical truth: PEC certifies delivery — not authenticity. If a government employee loses their password, if their device is infected, or if a malicious actor clones the address (a technique called ‘domain spoofing’), the system has no way to stop it.

This isn’t theoretical. Since the start of 2026, the Italy Cybersecurity Agency (CERT-AGID) has processed 650 confirmed cases of abused PEC accounts — many originating from state departments. The Reggio Calabria Prefecture has denied involvement, and investigators are still determining whether this was credential theft, cloning, or a broader infiltration. But the lesson is clear: if your organization trusts PEC without secondary verification, you’re already compromised.

What This Means for Residents

If you’re a Revolut user with crypto holdings: Assume your data was seen. Monitor unusual transactions. File a report with your bank and monitor your identity through Poste Italiane’s identity protection portal — free and accessible to all Italian citizens.

If you receive an official PEC request — from tax offices, utility providers, or even courts — never act on it alone. Always:

Call the institution using a number from their official website (not one listed in the email)

Avoid clicking links — download forms manually

If it’s urgent, ask for a second confirmation via registered mail or in person

The attack didn’t target Italian citizens directly — but the vulnerability is everywhere. Any entity relying on PEC as an unchallengeable signal of trust is at risk. This is now a nationwide awareness issue.

The Systemic Response

The Italy National Anti-Mafia Directorate has taken jurisdiction, a rare step indicating how seriously officials now view PEC abuse as a public order threat. Meanwhile, the National Cybersecurity Agency (ACN) fast-tracked deployment of stricter email authentication protocols across 21,000 public bodies — starting October 1, 2026.

By year-end, all government PEC accounts must enable double-verification for external requests and integrate with the new centralized identity verification portal — meaning emails will be flagged if the sender’s credentials don’t match a known, active government profile.

Additionally, EU-wide NIS2 compliance has compelled public institutions to undergo mandatory cybersecurity audits. The goal: stop treating trust as automatic.

This breach didn’t come from abroad. It came from inside — from the very infrastructure Italians rely on to believe in the state’s digital reliability. And the remedy isn’t more firewalls. It’s skepticism.

The system didn’t fail because of weak passwords. It failed because everyone assumed the email was real — and stopped asking why.

Author

Giulia Moretti

Political Correspondent

Reports on Italian politics, EU affairs, and migration policy. Committed to cutting through the noise and delivering balanced analysis on issues that shape Italy's future.