Technology
Cointelegraph.com News

Italy investigates government email breach linked to Revolut data leak

Source Entity

Cointelegraph by Helen Partz

September 16, 2026
Italy investigates government email breach linked to Revolut data leak

Italian authorities are investigating a significant security breach where a compromised government email account was used to illicitly access Revolut customer data. The incident, involving over 650 cases of fraudulent activity, has triggered a probe by the Polizia Postale into unauthorized computer access.

The Intersection of Public Infrastructure and Private Data

The recent security incident in Italy, where a government-linked email account was weaponized to target Revolut customer data, highlights a critical vulnerability in the digital ecosystem: the trust placed in government-issued communication channels. By leveraging a compromised certified email account, attackers successfully bypassed standard security filters that might otherwise flag unauthorized requests, demonstrating a sophisticated "living off the land" technique that exploits institutional credibility to facilitate cyber fraud.

The Mechanics of the Breach

Italian authorities, specifically the Polizia Postale, are currently investigating the breach under statutes related to unauthorized access to computer systems and computer fraud. The core of the issue lies in the misuse of certified email accounts, which are designed to provide legal proof of delivery and identity. When these accounts are compromised, they become potent tools for social engineering. In this instance, the attackers allegedly utilized a compromised account linked to the Prefecture of Reggio Calabria to solicit sensitive information from Revolut, effectively weaponizing the state's own digital infrastructure.

Challenges in Attribution and Denial

One of the most complex aspects of this investigation is the discrepancy between the reported breach and the official response from the targeted prefecture. While the agency has publicly denied sending requests to Revolut, the existence of over 650 cases of abuse suggests a systemic failure in account security. Revolut’s refusal to name the specific agency involved underscores the legal and diplomatic sensitivities inherent in cross-sector cyber investigations, where private fintech firms must balance transparency with the protection of ongoing law enforcement inquiries.

Broader Implications for Fintech Security

This incident serves as a stark reminder that even the most robust private-sector security protocols can be undermined by weaknesses in public-sector digital identity management. Fintech platforms like Revolut, which manage vast amounts of sensitive financial data, are increasingly becoming targets for sophisticated actors who seek to exploit the weakest link in the digital chain—often the human or administrative element. The potential for large-scale data exfiltration through government-backed channels poses a significant threat to consumer trust and regulatory compliance.

Future Trends in Cyber Defense

Looking ahead, this breach will likely force a reassessment of how private institutions verify requests originating from government agencies. We can expect to see a push for more stringent multi-factor authentication requirements and perhaps a move away from traditional email as a primary method for inter-organizational data requests. As digital fraud continues to evolve, the necessity for a more integrated and hardened framework between public administration and private enterprises becomes increasingly paramount to preventing such large-scale exploitation.

Verification Required?

Read the full report from the primary source

Go to Cointelegraph.com News