Hackers breach Revolut using Reggio Calabria Prefectural Authority email: investigation opened
The Prosecutor's Office of Reggio Calabria is investigating a cyber attack on Revolut through a compromised institutional email account. The "iamnotavillain" group is demanding 3 million dollars in ransom.

Investigation in Reggio Calabria into hacker attack on Revolut via ministerial certified email
The Prosecutor's Office of the Republic of Reggio Calabria has opened a case file on the Revolut incident, the British digital bank whose systems were compromised by a group of hackers who operated by exploiting a certified email (PEC) mailbox belonging to the Prefectural Authority of Reggio Calabria. This is reported by tg24.sky.it. The alleged offence is that provided for under article 615 ter paragraph 3 of the criminal code: intrusion into a computer system of public interest.
The National Anti-Mafia and Anti-Terrorism Directorate has also been activated on the matter, which is competent when the violation concerns a government body. The Postal Police has filed an initial report describing an operation of high technical sophistication. Investigators are seeking to establish whether the Prefectural Authority's PEC was actually compromised or simply cloned.
The "iamnotavillain" group and public claim of responsibility
The criminal collective, operating under the name "iamnotavillain", contacted the Financial Times via Telegram claiming responsibility for the attack. According to what was stated to the City newspaper, the group allegedly obtained confidential data of approximately 700 Revolut customers by impersonating Italian law enforcement officers for months and sending the bank formal requests for addresses, telephone numbers and transaction histories through the compromised PEC system.
The group also claims to hold approximately 147 gigabytes of internal data from Italian law enforcement agencies and has made a ransom demand of 6,000 XMR — equivalent to approximately 3 million dollars — with a 24-hour ultimatum, threatening otherwise to sell the information to other criminal organisations. The acronym XMR denotes Monero cryptocurrency, frequently chosen for unlawful purposes due to the difficulty in tracing its transactions.
The Financial Times emphasised how the public extortion demand represents an unusual approach: international hacker groups typically resort to private pressure, making stolen data known on the dark web only in case of non-payment. In this case the message was instead sent directly to the newspaper. Following publication, the newspaper also received video images — with scheduled self-destruction after 60 seconds — that allegedly show network movements through caches containing purported documents extracted from Revolut. The group told the Financial Times it had not initiated any negotiation with the bank and had chosen for the first time the path of public extortion.
Violated data: 680 European account holders
Overall, the intrusion allegedly compromised the personal data — but not the funds — of approximately 680 account holders of the digital bank residing in various European countries. The information extracted would include passport details, driving licences, other identity documents and verified photographs.
The Privacy Authority activates controls
The Privacy Authority has ordered an immediate review of any vulnerabilities in the access systems of Italian banking institutes, with the aim of ascertaining whether there have been further attempted infiltrations similar to the Revolut case. The Authority sent a communication to the network of data protection officers (DPO) of banking institutes, inviting them to conduct an internal review and to promptly report any flaws discovered.
The Authority has also taken action at European level, activating an information exchange channel with the corresponding Lithuanian authority — the country in which Revolut has its principal registered office — to strengthen coordinated counter-action. A discussion has also been opened with the Ministry of the Interior to frame the matter more thoroughly, to establish whether other banks or financial institutions have been involved, and to ascertain the overall extent of the compromised data.
Source: Google News IT — Crime (it)