Criminals used a legitimate government email domain to obtain sensitive customer records. Understand how it happened, what remains unverified, and what your team should check before answering its next request.
The breach and its aftermath: customer records, competing hacker claims, and reported ransom demands. A sourced account of what happened and what remains unresolved.
How the requests appeared legitimate: why a genuine government email can carry a fraudulent request, and how criminals buy access to police accounts.
What to check at your company: what Kodex recorded before the disclosure, how different verification checks work, and four questions to guide a review of your own requests.
Revolut says it disclosed customer records after receiving fraudulent requests from a legitimate government email domain. The exposed information included identity documents, verification selfies, and financial records. Reporting has since linked the requests to an Italian prefecture and described a campaign lasting months. Rival claimants have disputed responsibility, while reported ransom demands have added to the uncertainty. The report follows those developments and distinguishes confirmed statements from unresolved claims.
An attacker controlling a real agency mailbox may send messages that pass email authentication. Italy’s certified email system can also provide a valid delivery record without establishing the sender’s authority to request customer data. The market for that access predates the Revolut disclosure. Listings collected by Kodex advertised Italian police email accounts for $200 and an EU police account for $1,000, with a matching forged ID offered for another $300.
Kodex flagged Italian police and Interior Ministry certified-email domains in January. Several accounts on the domain later identified in reporting attempted to register with Kodex during 2026. None passed verification. The report explains what those findings establish, how they inform verification, and what to look for in your own records: who requested the data, how they were checked, what was disclosed, and whether related requests reached other teams.
We use cookies to keep the site running, understand how it's used, and measure our marketing. You choose what to allow — read more in our Privacy Policy.