The Incident Under Criminal Investigation
Italian law enforcement has opened a formal probe into a breach that appears to have enabled the unauthorized extraction of Revolut customer information. According to the Italian news agency ANSA, which reported the development on Tuesday, the Polizia Postale — the national cybercrime unit — is examining the matter on charges of unauthorized access to a computer system and computer fraud. The core allegation is that threat actors gained control of a government email address and leveraged it to request sensitive client data from the digital banking platform.
Several Italian outlets initially identified the compromised mailbox as belonging to the Prefecture of Reggio Calabria. That office subsequently told ANSA it had not sent any data requests to Revolut, distancing itself from the incident. Revolut, in turn, has refused to name the specific agency involved, pointing to the ongoing police inquiry and its own confidentiality obligations. A company spokesperson confirmed to Cointelegraph that Revolut notified Italian authorities as soon as the anomaly was detected and pledged full cooperation. The firm also stressed that its internal systems, databases, and customer funds were not compromised.
How the Certified Email Channel Was Abused
The compromised mailbox was reportedly part of Italy's Posta Elettronica Certificata (PEC) infrastructure, a certified electronic mail service designed to give electronic messages the same legal standing as a registered letter. In practice, this means financial institutions and other regulated entities often treat PEC communications as authoritative, making them a high-value target for social-engineering attacks.
Italy's CERT-AGID cybersecurity agency issued a public warning in June drawing a critical distinction: the PEC system verifies that a message was delivered, but it does not guarantee the integrity or security of the content within that message. The agency disclosed that it had processed more than 650 cases involving the misuse or illicit exploitation of PEC accounts since the beginning of 2026, a figure that signals a growing pattern of abuse rather than an isolated incident.
Risk Signals for Traders and Fintech Users
For anyone holding accounts with digital banks, payment platforms, or regulated financial services, this case highlights several practical risk factors worth monitoring:
- Institutional email spoofing remains a primary attack vector. Even when the source address appears to belong to a legitimate government or regulatory body, the underlying account may have been hijacked. Always verify unusual data requests through a second, independent channel.
- Certified delivery does not equal certified sender. As CERT-AGID made clear, PEC confirms transmission, not authenticity of intent. Financial institutions should, and in many jurisdictions must, have secondary verification steps before acting on data-access requests.
- Regulatory and law-enforcement timelines matter. The fact that the investigation is still active and that Revolut is bound by confidentiality means the full scope of the breach — including how many customers were affected and whether any data was exfiltrated — may take weeks to clarify. Users should watch for official notifications from their providers and avoid acting on unverified third-party claims.
The broader takeaway for the forex and fintech trading community is that supply-chain trust in institutional digital channels is not absolute. A single compromised mailbox at a government body can be turned into a credible-looking pretext for data harvesting, and the 650-plus PEC abuse cases logged by CERT-AGID this year suggest this is a systemic exposure, not a one-off event.