Doctorcrypto About RSS Subscribe
Doctorcrypto
HomeBusiness › Italy investigates government email breach linked to Revolut data leak
Business

Italy investigates government email breach linked to Revolut data leak

By Diego Whitfield · · 2 min read

Italian authorities have launched an investigation into a breach affecting government-linked certified email accounts, an incident that has been connected to a data leak involving fintech giant Revolut.

What Investigators Found

Italy's national cybersecurity agency flagged more than 650 cases in which certified email accounts were either abused or used illicitly. Certified email, known in Italy as PEC, carries legal weight equivalent to registered mail and is widely used for official communications between citizens, businesses, and public institutions.

The scale of the incident has raised alarm because compromised PEC accounts could be exploited to impersonate legitimate senders, deliver fraudulent documents, or facilitate broader phishing campaigns. Authorities are now working to determine how the accounts were accessed and whether sensitive government correspondence was exposed.

Certified email in Italy carries the same legal standing as registered mail, making any breach a serious threat to official communications.

The Revolut Connection

The probe reportedly ties back to a data leak associated with Revolut, one of Europe's largest digital banking platforms. Investigators are examining how information linked to the fintech may have played a role in enabling the abuse of the certified email system.

For a company operating at Revolut's scale, any association with a security incident invites intense regulatory scrutiny, particularly under Europe's strict data protection framework. The firm has faced growing pressure to demonstrate robust safeguards as it expands its customer base across the continent.

Key concerns for authorities include:

  • How attackers obtained access to certified email credentials
  • Whether personal data from the leak was used to target victims
  • The potential for further fraud stemming from compromised accounts

The investigation remains ongoing, and officials have yet to disclose the full extent of the damage or attribute the breach to a specific actor. The case underscores mounting worries over the security of digital infrastructure that bridges traditional institutions and modern fintech services.

Was this useful?👍 Yes👎 No