Add the Gazzetta del Sud as a source

They didn’t force the front door. They asked politely: “I’m the police, can I come in?” And it was opened to him. A group of hackers managed to obtain sensitive data – passports, identity cards, bank accounts, Bitcoin transactions – of several hundred account holders of the English bank Revolut, 680 according to an estimate by the Financial Times, using a compromised email from an Italian institution: the Prefecture of Reggio Calabria, apparently. In addition to the English authorities, the postal police are also investigating the case for unauthorized access to the computer system and computer fraud.
The false requests and the five months before the discovery
The fintech bank plays it down: “Revolut’s systems and customer funds were not affected.” But the data breach was sensational due to the way in which it was carried out. In fact, it seems that the scam continued for about five months, with requests spread over several periods before being discovered. To avoid arousing the bank’s suspicions, the fact that they came from an institutional PEC with the domain interno.it and were signed “Postal Police”.
Financial institutions are required by law to comply with official requests from law enforcement or government agencies. The requests appeared to be accompanied by valid technical authentication of the domain and were therefore processed as part of the ordinary procedures for fulfilling legal obligations.
In reality, there were signals that could have made the antennas stand up: the requests signed by the Postal Police on the certified e-mail of the Prefecture of Reggio Calabria, when the postal police has its own certified e-mail. Furthermore, the requests, in these cases, are accompanied by the decree of the judicial authority, something that appears to have been missing in the communications sent by the hackers.
Revolut’s response and Codacons’ request
Revolut reported a “sophisticated external impersonation scam, in which an unauthorized third party used an email address belonging to a legitimate government agency domain to make fraudulent requests for information. As soon as the fraud was identified – he underlined – we immediately blocked the address and informed the relevant government agency, as well as law enforcement authorities, data protection authorities and financial supervisory authorities. We have contacted the limited number of people involved directly to inform them of the incident and provide them with assistance.”
Among the victims is also the French entrepreneur Mark Robert Karpelès, who protested: “Revolut should not have sent customer data in response to an email just because it came from a government agency.”
Codacons intervenes, asking “the competent authorities to take action to ascertain the dimensions of the phenomenon, whether and how many Italian institutions have been violated by cyber criminals and which certified electronic mail certificates have been used to steal sensitive data”.