Italian Prosecutors Open Investigation Into Revolut Extortion Campaign
Italian prosecutors have opened a formal investigation into an alleged extortion campaign targeting hundreds of Revolut customers, according to reporting on the case. The probe follows claims that criminals obtained sensitive customer information and are now using it to pressure the fintech company into a massive cryptocurrency payout. The attackers reportedly demanded 6,000 Monero (XMR), a privacy-focused cryptocurrency, in exchange for not selling or leaking the stolen data.
This is not the first time Revolut customers have been caught up in a data extortion scheme. Earlier incidents saw hackers leak passports and selfies while demanding ransom and threaten to release data belonging to 680 customers if their demands went unmet. The latest development, with Italian authorities now formally investigating, marks an escalation in both scale and legal seriousness.
How the Data Was Reportedly Obtained
What sets this case apart from typical breach stories is the method allegedly used to access customer data. Reports indicate the attackers compromised a government-linked certified email account, known in Italy as a PEC (Posta Elettronica Certificata), and used that access to extract information tied to Revolut accounts. Certified email systems are widely used across Italy for legally binding communications between businesses, individuals, and public institutions, which means a single compromised account can potentially open a door to a wide range of sensitive correspondence.
This detail matters because it shifts part of the story away from Revolut's own security infrastructure and toward the broader ecosystem of institutional email systems that fintech companies and their customers rely on indirectly. It echoes a pattern seen in Revolut's earlier extortion crisis, where the company emphasized that no direct hack of its own systems had occurred, yet customers still faced real exposure through third-party channels.
Italy's Probe and Revolut's Response
Prosecutors are now examining how the compromised email account was accessed and how far the resulting data exposure extends. The investigation adds an official law enforcement dimension to a story that, until now, had largely played out through public ransom threats and dark web leak announcements. For Revolut, the company has reportedly stated it had not received direct contact from the hackers despite the public demand, a stance consistent with earlier episodes where the company distanced itself from direct negotiation while facing extortion demands after previous breaches.
The use of Monero, rather than Bitcoin or another more traceable cryptocurrency, is also worth noting. Monero's design prioritizes transaction privacy, making it significantly harder for investigators to trace payments if a ransom is ever paid. That choice suggests the attackers are aware that law enforcement scrutiny is likely and are attempting to minimize their exposure accordingly.
What This Means For You
If you're a Revolut customer, or a customer of any digital financial service, this case is a reminder that your exposure to data breaches doesn't stop at the company you signed up with. Data can move through partner systems, government email infrastructure, or other third parties in ways that are largely invisible to the end user. You can't control every link in that chain, but you can control how you respond when a breach becomes public.
Watch for official communication from Revolut through verified channels only, and treat unsolicited messages referencing the breach with suspicion, especially anything asking you to click a link, verify your identity, or make a payment. Extortion campaigns like this one often generate secondary phishing attempts that target the same customer base a second time, capitalizing on the fear and confusion the original breach created.
Actionable Takeaways
If you believe your data may have been affected by this or a related Revolut incident, consider taking the following steps. Change your Revolut password and enable two-factor authentication if you haven't already. Monitor your account statements closely for unfamiliar activity over the coming weeks. Be skeptical of any email, text, or call claiming to be from Revolut regarding this breach, and verify requests directly through the official app rather than clicking links. Consider placing a fraud alert or credit freeze if identity documents such as passports were among the data potentially exposed.
The investigation into this Revolut extortion case is still unfolding, and Italian prosecutors will likely uncover more details about how the compromised email account was accessed and how many customers are truly affected. In the meantime, staying alert to phishing attempts and securing your own account settings remains the most reliable way to limit your personal risk while the larger story plays out.




