Hackers breach Italian state email to target Revolut crypto users

1 hour ago 2



Someone hijacked a legitimate Italian government email address, used it to impersonate law enforcement, and convinced Revolut to hand over personal data belonging to roughly 700 customers. The attackers then turned around and demanded 10,000 Bitcoin from their victims. The breach, which occurred around September 11-12, exposed identity documents, passports, verification selfies, IBANs, and Bitcoin transaction histories. How the scam worked The attackers compromised an email account on the @interno.it domain, which belongs to Italy’s Ministry of Interior. With that credential in hand, they sent what appeared to be official emergency data requests to Revolut, the London-based fintech giant that serves millions of users across Europe. Emergency data requests are a standard mechanism that law enforcement agencies use to obtain user information from tech companies without a court order, typically in cases involving imminent danger. The system relies heavily on trust: if the email looks right and comes from the right domain, companies often comply quickly. Revolut processed the fraudulent requests and shared personal data from between 680 and 700 users before anyone realized something wa...

Read Entire Article