HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Compromised Italian Government Email Enables Fraudulent Data Requests, Exposing 680 Revolut Customers

Attackers who seized an Italian government PEC account impersonated officials and obtained personal, banking and crypto transaction data for about 680 Revolut users. The breach underscores the need for verified third‑party request processes and continuous monitoring of supplier security.

Verisq™ Intelligence · 📅 September 17, 2026 · 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
securityaffairs.com

Compromised Italian Government Email Enables Fraudulent Data Requests, Exposing 680 Revolut Customers

What Happened — Attackers who gained control of an Italian government PEC mailbox impersonated law‑enforcement officials and sent fraudulent data‑request emails to Revolut. The fintech firm complied, resulting in the exposure of personal, banking and cryptocurrency transaction data for roughly 680 customers. Revolut confirmed its internal systems were not breached.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of relying on unauthenticated external communications – a scenario a continuous third‑party risk‑management program is built to detect and document.
  • Highlights the need for verifiable request‑validation controls and audit‑ready evidence that every data‑release request follows a vetted process.
  • Shows how a compromised supplier (government email service) can become a conduit for data leakage, stressing the importance of ongoing monitoring of third‑party security posture.

Who Is Affected – Financial services / payments providers; any organization that processes sensitive customer data and accepts external data‑request emails.

Recommended Actions

  • Map the incident to your third‑party risk‑assessment controls and verify that all external data‑request channels require multi‑factor authentication and documented approval.
  • Collect and retain evidence of request validation (e.g., signed orders, call logs) to support audit readiness under NIST CSF 2.0 Governance & Risk Management.

Technical Notes – The attackers leveraged a compromised PEC (certified email) account belonging to the Prefecture of Reggio Calabria (pec.interno.it). No vulnerability in Revolut’s platform was exploited; the breach stemmed from social engineering of a trusted government channel. Source: Security Affairs

📰 Original Source
https://securityaffairs.com/199180/data-breach/revolut-data-leak-may-trace-back-to-compromised-italian-government-accounts.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →