Italian authorities are investigating a government email breach that is allegedly linked to the leak of Revolut customer data. Hackers reportedly used a compromised certified email account to gain access to sensitive customer information.
Polizia Postale, Italy’s cybercrime police, is investigating the incident for alleged unauthorized access to a computer system and computer fraud, according to Italian news agency ANSA. Some Italian media reports identified the compromised account as belonging to the Prefecture of Reggio Calabria, but the agency later denied sending requests to Revolut.
Revolut declined to identify the specific government agency involved, citing the ongoing police investigation and confidentiality. A Revolut spokesperson confirmed the company reported the incident to Italian authorities upon detection and will assist as needed, adding that the company’s systems, databases, and customer funds remained secure.
The compromised government email account was reportedly part of Italy’s Posta Elettronica Certificata (PEC) system, a certified email service that provides messages with the same legal standing as registered mail. However, Italy’s CERT-AGID cybersecurity agency warned in June that while PEC certifies delivery, it does not guarantee the security of a message's content. The agency stated it had handled over 650 cases involving abused or illicit PEC accounts since the beginning of 2026.