Italy Launches Inquiry Into Email Hack Allegedly Used to Steal Revolut Data

Revolut
Table of Contents

TL;DR:

  • Italy have opened a criminal investigation after a hack on government email accounts was used to obtain sensitive data from Revolut customers.
  • The Polizia Postale is handling the case for alleged unauthorized access to computer systems and computer fraud; some media outlets point to the Prefecture of Reggio Calabria.
  • The PEC system, which grants legal value to certified emails, has recorded more than 650 cases of illegal accounts since January 2026.

Italy have opened a criminal investigation after a hack on government email accounts was detected, reportedly carried out to obtain sensitive data from customers of Revolut.

The Polizia Postale, the cybercrime unit of the Italian police, is leading the investigation for alleged unauthorized access to computer systems and computer fraud, according to the ANSA news agency.

According to some media outlets from Italy, the compromised account would belong to the Prefecture of Reggio Calabria, although the agency subsequently denied having sent any requests to Revolut.

Italy and Revolut: Few Details Due to the Police Investigation

The fintech company declined to identify the government agency involved, citing an active police investigation and confidentiality obligations. “We reported this to the authorities of Italy upon detecting it and will assist them as needed,” a company spokesperson stated, adding that Revolut’s systems, databases, and customer funds were and remain secure.

Revolut italy hack

The Vulnerability of the PEC System

The compromised account would have been part of the Posta Elettronica Certificata (PEC) system, the certified email service that grants messages the same legal value as a paper certified letter.

The cybersecurity agency CERT-AGID warned in June 2026 that the PEC system guarantees the delivery of messages, but not the security of their content, a distinction that the attackers reportedly exploited to obtain confidential customer information.

Since January 2026, CERT-AGID has handled more than 650 cases related to PEC accounts that were abused or used illicitly, a figure that reveals a clear vulnerability in the State’s official communications infrastructure.

The incident has put pressure on a system designed to guarantee legal authenticity, but which lacks robust identity verification mechanisms against unauthorized access. The investigation remains open as authorities gather additional information with Revolut’s cooperation.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews