Revolut Data Breach Exposes Hundreds of European Users as Hackers Demand $3 Million
A cyberattack targeting popular fintech platform Revolut has compromised the personal data of approximately 700 European customers, with the perpetrators demanding a ransom of three million dollars in exchange for not exploiting or publishing the stolen information, according to reports emerging from Italy.
Prosecutors in Reggio Calabria, the southern Italian city at the tip of the peninsula’s boot, have launched a formal inquiry into the incident after investigators determined that hackers gained access to sensitive customer data through Italy’s certified electronic mail system, known as PEC — a legally recognised digital communication tool widely used across the country for official correspondence.
Certified Email System Exploited as Entry Point
The use of Italy’s PEC infrastructure as a vehicle for the breach raises serious questions about the security vulnerabilities inherent in institutional digital communication channels. PEC, or Posta Elettronica Certificata, is a system mandated for use by public bodies, legal professionals and businesses across Italy, lending it a degree of trust that cybercriminals appear to have sought to exploit. Officials said the investigation is ongoing and that authorities are working to identify those responsible.
Revolut, the London-headquartered neobank that has grown into one of Europe’s most widely used digital financial platforms with tens of millions of customers globally, has not been accused of any wrongdoing in the incident. The breach appears to have targeted data accessible through external communication pathways rather than representing a direct intrusion into Revolut’s core systems, though the full technical scope of the attack remains under investigation.
The ransom demand of three million dollars places this incident within a growing pattern of financially motivated cybercrime targeting the financial services sector across Europe. Criminal groups have increasingly turned their attention to fintech companies and their customer bases, recognising that financial data carries particularly high value on illicit markets and that affected institutions face reputational pressure to resolve such situations quickly.
For the roughly 700 European clients whose information is reported to have been compromised, the immediate risks include targeted phishing attempts, identity fraud and unauthorised access to linked financial accounts. Cybersecurity experts generally advise affected individuals to monitor their accounts closely, change passwords and enable multi-factor authentication where not already in use, while remaining alert to unsolicited communications purporting to be from their bank or financial provider.
The Reggio Calabria investigation adds to a broader caseload of cybercrime inquiries being pursued by Italian authorities, who have in recent years invested in dedicated digital forensics capabilities. Whether the suspected perpetrators are located within Italy or operating from abroad — as is common in ransomware and data extortion cases — remains unclear at this stage. European law enforcement agencies including Europol have increasingly coordinated cross-border responses to such incidents, and it is possible that the inquiry will expand in scope as evidence is gathered. Revolut has not made a public statement on the matter, according to available reports.
