Revolut confirmed that it had sent information about 680 customers to cybercriminals who had presented themselves as Italian authorities. The data provided included information from passports, home addresses, bank accounts, and transactions. The fraud was carried out over several months through messages sent to Revolut’s headquarters in Lithuania.
The scammers, who identified themselves as the “IAmNotAVillain” group, used a certified email address associated with the Prefecture of Reggio Calabria, an institution subordinate to the Italian Ministry of the Interior. In their requests, they invoked an alleged investigation by the Milan Public Prosecutor’s Office and European judicial cooperation instruments, including the European Investigation Order.
However, the messages contained several inconsistencies: the address in Reggio Calabria was being used for an investigation in Milan, while some protocol numbers were associated with the Rome Public Prosecutor’s Office. Nevertheless, on March 24, 2026, Revolut asked the criminals to correct the request’s letterhead, and at the beginning of May it apologized for the delay in transmitting the data and announced an internal audit.
In a message dated July 24, the bank confirmed that it had sent the documents and specified that 169 of the requested accounts were administered by its UK headquarters, for which a different procedure applied. Subsequently, the group demanded money and threatened to publish the data.
Italy’s Postal Police are investigating how the prefecture’s address was compromised.
Sources
Latest News
12:34
12:31
12:22
12:20
12:19
See more news