Hackers Infiltrate Italian Ministry Email to Extract Revolut Crypto Records
Italian authorities and European regulators are investigating after fraudsters compromised an account inside Italy’s Ministry of the Interior on the state-certified Posta Elettronica Certificata (PEC) email system, posing as police officers to obtain customer records from Revolut. Revolut complied with the certified requests over several months, handing over complete verification dossiers—including passport scans, selfies, home addresses, and Bitcoin transaction ledgers—for approximately 680 high-net-worth cryptocurrency holders. As lawmakers in Rome press the government to explain how state infrastructure was breached, affected customers are warning of extortion risks, and officials are assessing whether the same mailbox was used to target other financial institutions.
- Status:
- active
- Record updated:
Current state
Latest recordT
Timeline
- September 16, 2026
Italian Parliament Launches Inquiry
Italian lawmaker Giulia Pastorella formally questions the Ministry of the Interior over the breach of the state PEC network, asking for full disclosure and an investigation into whether peer institutions were targeted.
- September 14–15, 2026
Investigations Reveal PEC Infiltration and Scale
Reporting by the Financial Times and The Wall Street Journal reveals the source was Italy's Interior Ministry PEC system and that ~680 "crypto whales" across 33 countries were compromised, prompting fears of targeted extortion and physical attacks.
- September 12, 2026
Breach Publicly Disclosed
Revolut publicly confirms the disclosure following reporting by TechCrunch, stating internal databases and funds were unaffected; former Mt. Gox CEO Mark Karpelès reveals he was targeted.
- September 11, 2026
Notices Sent to Affected Users
Revolut begins privately emailing breach notices to affected customers, confirming that identity documents, selfies, and Bitcoin transaction records were exposed.
- Early September 2026
Fraud Discovered on Follow-Up
Revolut contacts the Italian ministry through separate channels to follow up; officials confirm the requests were unauthorized. Revolut blocks the sender address and alerts regulators.
- Summer 2026
Revolut Fulfills Data Demands
Accepting the legal presumption of the certified PEC transmission, Revolut compliance staff release customer identity and transaction files over several months without independent verification.
- May–August 2026
Italian State PEC Account Infiltrated
Attackers access an internal mailbox inside Italy’s Ministry of the Interior on the certified PEC network, identify high-balance crypto wallets via onchain analysis, and begin sending data requests to Revolut.
Related reporting
Revolut Disclosed Customer Passports and Bitcoin Histories to Fraudulent Government Requester
Revolut disclosed customer passports and Bitcoin transaction histories after fulfilling a fraudulent data request sent from an authentic government email domain. While customer funds remained safe, the incident leaked complete identity dossiers belonging to targeted cryptocurrency users.