Revolut Bank UAB processed 5 months of forged Italian Ministry of Interior requests after infostealer compromise of pec.interno.it account
Revolut processed forged Italian government data requests for five months after an infostealer compromise of a Ministry of Interior mailbox. 680 high-value accounts were exposed; the company claims no direct ransom contact. The case reveals verification gaps in cross-border legal request handling that extend beyond this single incident.
Revolut Bank UAB, the Lithuania entity, responded to fabricated law-enforcement demands sent from a compromised pec.interno.it mailbox for approximately five months. The actor used the mailbox to request customer data on cryptocurrency whales; no callback verification or signed request checks appear to have been applied. Roughly 147 GB of additional Italian police data was also obtained in the same campaign.
Hudson Rock telemetry shows over 300 compromised pec.interno.it credentials circulating in infostealer markets, indicating the initial access was purchased rather than targeted. Revolut has stated it received no direct ransom demand from IAmNotAVillain, yet the actor publicly posted samples and threatened sale. The Italian Ministry of Interior has opened an investigation but has not confirmed whether the mailbox owner was notified of the abuse.
The incident exposes a systemic pattern: fintech subsidiaries treat email-borne government requests as presumptively authentic when volume or formatting matches prior legitimate traffic. No published CVE or EDR rule specifically flags this workflow abuse. Similar mailbox takeovers have preceded breaches at other EU financial entities handling cross-border data requests.
Revolut faces probable administrative action from both Lithuanian and Italian regulators within 90 days. Expect mandatory callback procedures and signed PDF mandates for all future legal requests; failure to implement will trigger fines above €2 million.
Lithuanian Data Protection Authority: formal fine or remediation order issued within 90 days if callback verification is not demonstrably deployed.
Sources (2)
- [1]SecurityWeek Revolut Coverage(https://www.securityweek.com/revolut-data-breach-5-months-680-high-profile-accounts-3m-ransom/)
- [2]Hudson Rock Infostealer Intelligence Report(https://hudsonrock.com/reports/revolut-italian-ministry-compromise-2024)