In the realm of major cybersecurity incidents, the narrative typically revolves around complex zero-day exploits, sophisticated malware bypasses, or server breaches executed by unseen hackers. However, the breach targeting British fintech giant Revolut tells a vastly different and far more troubling story: the bank’s internal systems were never hacked—they were simply tricked.
Brought to light through detailed analyses by blockchain investigator ZachXBT and additional cybersecurity channels including International Cyber Digest and korraflow, the incident lays bare how blind trust in formal, government-sanctioned communication channels can turn bureaucratic protocols into a perfect Trojan horse.
The Operation: Misusing Judicial Channels and the Italian PEC Trap
The attack relied not on technical software vulnerabilities, but on a highly sophisticated form of executive social engineering aimed directly at Revolut’s legal and compliance teams.
The operation exploited standard Law Enforcement Requests—the emergency legal mechanisms through which law enforcement and judicial authorities routinely compel financial institutions to hand over sensitive account records for ongoing criminal investigations. To carry out the scheme, the threat actor operating under the alias IAmNotAVillain gained control of—or spoofed through infrastructure access—an official PEC (Posta Elettronica Certificata / Certified Electronic Mail) address belonging to Italian law enforcement or government departments.
Because the request originated from an authentic government domain equipped with valid technical authentication records (passing both SPF and DKIM checks) and backed by the legal standing of the Italian PEC system, it passed Revolut’s internal compliance protocols without triggering red flags. Believing they were fulfilling a mandatory legal order from Italian authorities, Revolut staff compiled the requested dossiers and transmitted them directly to the attackers, even sharing encryption keys over the same channel and effectively neutralizing standard security safeguards.
Targets and Exfiltrated Intelligence
While Revolut clarified that the absolute number of affected accounts was limited—and emphasized that no client funds were stolen nor app login credentials compromised—the choice of targets was far from random.
The attack was surgically tailored toward High-Net-Worth Individuals (HNWIs), corporate executives, athletes, and prominent figures within the cryptocurrency space, including Mark Karpelés, the founder of the former Mt. Gox exchange. Through these forged requests, the attackers managed to extract an estimated 147 GB archive containing complete Know Your Customer (KYC) dossiers:
- Biometric and Identity Verification Data: High-resolution scans of passports, driver’s licenses, and the original verification selfies submitted during onboarding.
- Comprehensive Financial Records: Full account statements, IBANs, complete transaction histories, withdrawal records, and detailed tracking of cryptocurrency movements (specifically Bitcoin).
Broader Fallout and Institutional Vulnerabilities
The implications of the breach extend well beyond the immediate operational impact on a single fintech platform, touching on several systemic vulnerabilities:
- Heightened Risk of Targeted Secondary Attacks: Possessing authentic biometric identity files alongside complete financial histories grants extortionists the raw material required for highly convincing spear-phishing campaigns, SIM-swapping, and targeted identity theft. Threat actors can impersonate banking officials or launch ransom attempts directly against victims (reports indicate the attackers subsequently demanded Bitcoin ransoms under threat of leaking the data).
- Structural Blind Spots in Certified Email Systems: The breach reignited serious debate over the verification standards surrounding Italy’s PEC framework. While PEC guarantees delivery and message integrity, cybersecurity experts point out that it does not inherently guarantee rigorous real-time verification of whether the sender’s identity matches the represented public institution, leaving room for exploitation when official accounts are compromised or improperly registered.
- Regulatory and Reputational Pressure: For Revolut, whose business model relies heavily on user trust and data integrity, the incident exposes a critical flaw in procedural security. Financial regulators and privacy watchdogs across Europe are now scrutinizing how easily emergency compliance workflows allowed entire KYC packages to be offloaded, proving once again that human and process vulnerabilities can readily bypass the most robust technical defenses.


