HomeNews
Share

Hack of the Italian State Post Office, the Hunt for "Whales": The FT Learns Details of the Revolut Data Breach

Hackers claim they spent months gathering information on major cryptocurrency holders by posing as Italian law enforcement officials

Albert Fahrutdinov

Albert Fahrutdinov

reporter Oninvest
A data breach affecting hundreds of Revolut customers occurred as the neobank was actively expanding into Western markets / Photo: Veja/Shutterstock.com

A data breach affecting hundreds of Revolut customers occurred as the neobank was actively expanding into Western markets / Photo: Veja/Shutterstock.com

Hackers who claimed responsibility for the Revolut customer data breach told the Financial Times (FT) that they had hacked into an Italian government email system and spent several months posing as law enforcement officials to obtain confidential information. According to them, they repeatedly requested the addresses, phone numbers, and transaction histories of specific customers. “Revolut obeyed like a good boy,” the FT quotes the alleged hackers as saying.

The screenshots that the hackers sent to the FT appeared to be correspondence between Revolut and a division of Italy’s Ministry of the Interior via the Italian certified email system (PEC)—the digital equivalent of a registered letter. This is a secure system that authorities, companies, and individuals in Italy use for official and legally significant correspondence. A source familiar with the matter confirmed to the newspaper that the requests were indeed sent via PEC and that the exchange of messages continued for several months.

Revolut told the FT that its own systems and databases had not been hacked: the scammers used an official communication channel to pass off their messages as legitimate requests from authorities. Europe’s most valuable startup confirmed the data breach on September 11, the newspaper notes.

The goal is “cryptokits”

According to the hackers, they targeted 680 Revolut customers with large cryptocurrency holdings. “I’d rather not reveal exactly how I did it, but it involved blockchain analysis,” the source told the FT, referring to the selected customers as “crypto whales.”

Most of these customers are from Switzerland and France, the hackers told the newspaper. According to them, Revolut also provided them with information about residents of 31 other countries, primarily in Europe.

The Wall Street Journal, citing a source close to Revolut, reports that approximately 680 people were affected out of a total customer base of over 80 million. As the publication notes, the breach drew attention because its alleged targets were wealthy participants in the cryptocurrency market.

Easier than robbing a bank

Customers of the neobank fear that the data breach will make them victims of “wrench attacks”—in which criminals use threats of violence to force Bitcoin owners to hand over the keys to their assets, according to the WSJ.

Among the victims is Felix Römer, a German crypto entrepreneur living in Malta. According to the WSJ, the scammer had obtained his home address, a photo of his passport, and a history of transactions from his Revolut account. “If you have cryptocurrency and your address has been compromised, it’s essentially an invitation to be robbed,” Römer told the newspaper. “It’s easier than robbing a bank.”

Mark Karpelès, the former head of the bankrupt Bitcoin exchange Mt. Gox, also said he was affected by the leak. “At the very least, they should have spoken to a real person to verify it,” he wrote on X.

The tip of the iceberg

Italian law enforcement agencies and relevant government departments declined to comment, but officials confirmed that investigations are underway, according to the FT. Giulia Pastorella, a lawmaker from the Italian opposition party Azione, demanded immediate explanations from Italy’s Ministry of the Interior regarding reports of a hack into the ministry’s PEC email system. “We may be seeing only the tip of the iceberg,” she wrote on social media, asking, “How many more companies have fallen victim to this scheme?” (quoted in the FT).

The identities and motives of the attackers remain unknown, the FT notes. According to a source who spoke with the newspaper, Revolut has not yet received any offers to buy back the stolen data.

The WSJ notes that the news of the data breach came at an “inopportune” time for Revolut: in recent months, the fintech has been actively expanding the geographic reach of its banking operations. In March 2026, the company received a full banking license in the United Kingdom; in July, it received the same license in Australia; in August, it received a license in France; and in September, it received preliminary approval to provide banking services in the United States.

This article was AI-translated and verified by a human editor

Share

Trending

Stock Screener
Buy
Sell






















Small Caps
Investment and Finance News