Compromised Italian Government Email Enables Fraudulent Data Requests, Exposing 680 Revolut Customers
What Happened — Attackers who gained control of an Italian government PEC mailbox impersonated law‑enforcement officials and sent fraudulent data‑request emails to Revolut. The fintech firm complied, resulting in the exposure of personal, banking and cryptocurrency transaction data for roughly 680 customers. Revolut confirmed its internal systems were not breached.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of relying on unauthenticated external communications – a scenario a continuous third‑party risk‑management program is built to detect and document.
- Highlights the need for verifiable request‑validation controls and audit‑ready evidence that every data‑release request follows a vetted process.
- Shows how a compromised supplier (government email service) can become a conduit for data leakage, stressing the importance of ongoing monitoring of third‑party security posture.
Who Is Affected – Financial services / payments providers; any organization that processes sensitive customer data and accepts external data‑request emails.
Recommended Actions
- Map the incident to your third‑party risk‑assessment controls and verify that all external data‑request channels require multi‑factor authentication and documented approval.
- Collect and retain evidence of request validation (e.g., signed orders, call logs) to support audit readiness under NIST CSF 2.0 Governance & Risk Management.
Technical Notes – The attackers leveraged a compromised PEC (certified email) account belonging to the Prefecture of Reggio Calabria (pec.interno.it). No vulnerability in Revolut’s platform was exploited; the breach stemmed from social engineering of a trusted government channel. Source: Security Affairs