Why is Italy investigating Revolut over 650 government email breaches in 2026?

Italy's National Cybersecurity Agency is investigating over 650 cases of compromised certified email accounts linked to a major data leak at the fintech giant Revolut. The probe focuses on how stolen user credentials from the financial platform were exploited to gain illicit access to sensitive government communication systems.
Why is Italy investigating Revolut over 650 government email breaches in 2026?

Italy has launched a formal investigation into a series of cyberattacks targeting its 'Posta Elettronica Certificata' (PEC) system, with evidence pointing to a significant data leak at Revolut as the source of the compromised credentials. According to the Italian National Cybersecurity Agency (ACN), more than 650 government-linked email accounts have been abused or illicitly accessed, raising alarms over the security of state infrastructure when tethered to private fintech data. The breach highlights a critical vulnerability where personal data from a crypto-friendly neobank is being leveraged to infiltrate legally binding administrative channels.

The investigation centers on how hackers utilized the leaked Revolut data to bypass security measures for the PEC system, which serves as the digital equivalent of registered mail for Italian citizens and officials. This incident has sparked a broader debate within the European Union regarding the security responsibilities of digital-first financial institutions. Regulators are particularly concerned that the intersection of traditional finance, crypto services, and government identity verification is creating a new, expanded attack surface for sophisticated cybercriminals.

For the crypto and fintech markets, this development is a reminder of the mounting regulatory pressure facing platforms that handle both fiat and digital assets. As Revolut continues to expand its footprint in the European crypto space, this security failure could lead to stringent new oversight from the European Data Protection Board (EDPB) and potential fines under GDPR. The incident underscores that a data breach in the private sector can quickly escalate into a national security concern if the data is recycled for credential stuffing against public institutions.

Investors and users should watch for the ACN's final report on the breach's technical specifics and any subsequent legal action taken by the Italian Data Protection Authority (Garante). There is also a possibility that other EU nations may report similar breaches if their citizens' data was part of the same Revolut leak. In the coming months, expect a push for mandatory multi-factor authentication (MFA) upgrades across all financial platforms operating within the Eurozone to prevent the reuse of compromised passwords in government portals.

Editorial method

This report is based on the linked source and is labeled with its publication date, provider, category and market-impact assessment. Market interpretation is informational, not investment advice.