> > Hacker iamnotavillain steals data from 700 Revolut users

Hacker iamnotavillain steals data from 700 Revolut users

Hacker iamnotavillain steals data from 700 Revolut users

Hacker iamnotavillain impersonated an official and stole data from hundreds of Revolut customers, attracting the attention of the Postal Police and DNA.

British fintech company Revolut, known for its rapid delivery of digital financial services, was recently at the center of a serious cyber breach. According to initial reports, the personal data and transaction histories of approximately 700 account holders were compromised by a sophisticated attack, which also resulted in access to approximately 147 gigabytes of internal data held by Italian law enforcement agencies.

The alleged perpetrators of the attack are a cybercriminal group operating under the pseudonym iamnotavillain . The group stated, via a Telegram channel, that for months they maintained the illusion of being Italian authorities personnel in order to obtain customers' addresses, phone numbers, and banking details from Revolut.

The confession was sent to the Financial Times but the authorities confirmed its veracity.

Computer fraud through the Reggio Calabria Prefecture account

The investigation focused on a certified email (PEC) account associated with the Prefecture of Reggio Calabria. According to initial reports, the hackers used this account to impersonate employees of the Ministry of the Interior, requesting information from Revolut as if it were an official request.

Authorities are still evaluating whether the certified email address was actually compromised or simply cloned, a common phenomenon in advanced phishing operations . This modus operandi allowed iamnotavillain to collect the same data from nearly 700 users over a period of several months.

Technical details on the alleged compromise of PEC

Law enforcement officials have hypothesized that the connection between the certified email and the bank occurred by exploiting vulnerabilities in the Ministry of the Interior 's management of login credentials . The technique, described as "highly sophisticated" in the initial Postal Police report , may have involved the creation of a digital replica of the mailbox, capable of intercepting communications without the legitimate owner's knowledge. This scenario makes it difficult to establish with certainty whether the breach was the result of a direct attack or digital identity cloning.

Reaction from the authorities: Postal Police and National Anti-Mafia and Anti-Terrorism Directorate

The Postal Police has opened a criminal investigation to shed light on the entire operation, describing it as one of the most structured frauds in recent years. At the same time, the National Anti-Mafia and Counterterrorism Directorate (DNA) has intervened, as the breach involves a government agency. DNA magistrates have initiated the necessary procedures to assess possible links to broader criminal networks, given the involvement of a state agency in the data collection phase.

Monitoring the dark web for possible data sale

Another line of investigation is focused on the dark web , where hackers often sell sensitive information. Investigators are tracking any ads offering Revolut records or the 147 GB of law enforcement data to prevent further dissemination or misuse. No concrete evidence of a transaction has emerged so far, but monitoring remains active and intensified.

The case highlights the vulnerability of certified communication systems and the need to strengthen authentication procedures when processing requests for sensitive data. While the investigation continues, Revolut has already warned its customers of potential fraudulent activity and is working with authorities to mitigate the damage. This incident serves as a warning to institutions and fintech operators, who must review their security protocols to prevent similar scams from happening again.

Continue on the app The news of your city, in real time.
Open in app