The Revolut data exposure may be part of a much broader cyber incident involving compromised Italian government infrastructure.
Revolut has confirmed that its systems were not breached. Instead, the company received fraudulent requests that appeared to originate from a legitimate Italian government domain. The attackers allegedly abused an authentic institutional communication channel to obtain sensitive information on Revolut customers.
According to information reported so far, the compromised account was allegedly associated with the Prefecture of Reggio Calabria and used the pec.interno.it domain. The mailbox was reportedly abused by individuals posing as Italian Postal Police officers.
by Security Affairs – Revolut Data Leak May Trace Back to Compromised Italian Government Accounts



