Italy has launched a formal investigation into a series of cyberattacks targeting its 'Posta Elettronica Certificata' (PEC) system, with evidence pointing to a significant data leak at Revolut as the source of the compromised credentials. According to the Italian National Cybersecurity Agency (ACN), more than 650 government-linked email accounts have been abused or illicitly accessed, raising alarms over the security of state infrastructure when tethered to private fintech data. The breach highlights a critical vulnerability where personal data from a crypto-friendly neobank is being leveraged to infiltrate legally binding administrative channels.
The investigation centers on how hackers utilized the leaked Revolut data to bypass security measures for the PEC system, which serves as the digital equivalent of registered mail for Italian citizens and officials. This incident has sparked a broader debate within the European Union regarding the security responsibilities of digital-first financial institutions. Regulators are particularly concerned that the intersection of traditional finance, crypto services, and government identity verification is creating a new, expanded attack surface for sophisticated cybercriminals.
For the crypto and fintech markets, this development is a reminder of the mounting regulatory pressure facing platforms that handle both fiat and digital assets. As Revolut continues to expand its footprint in the European crypto space, this security failure could lead to stringent new oversight from the European Data Protection Board (EDPB) and potential fines under GDPR. The incident underscores that a data breach in the private sector can quickly escalate into a national security concern if the data is recycled for credential stuffing against public institutions.
Investors and users should watch for the ACN's final report on the breach's technical specifics and any subsequent legal action taken by the Italian Data Protection Authority (Garante). There is also a possibility that other EU nations may report similar breaches if their citizens' data was part of the same Revolut leak. In the coming months, expect a push for mandatory multi-factor authentication (MFA) upgrades across all financial platforms operating within the Eurozone to prevent the reuse of compromised passwords in government portals.