CYBERSECURITY · ANALYSIS

Revolut case: How an Institutional Address Was Able to Be Used for a Data Leak

An Italian PEC was reportedly used to obtain the data of hundreds of Revolut customers. The known facts, the KYC issue, and the privacy questions.

Published on 2 min read

Revolut case: How an Institutional Address Was Able to Be Used for a Data Leak 1

Revolut transmitted customer data to fraudsters posing as a public authority. Around 680 people are believed to be affected, according to a Financial Times estimate relayed by ANSA on September 15.

An Italian PEC used to obtain the data

The requests reportedly came from an Italian certified email service, a PEC linked to the prefecture of Reggio Calabria, which was allegedly compromised. PEC (Posta Elettronica Certificata) is an Italian certified email system that provides proof of the sending and receipt of messages. Identity documents, banking information, and transaction histories are among the data mentioned. The Italian postal police are investigating, ANSA reports.

Revolut says that its systems and customers’ funds were not affected. The bank says it blocked the address, alerted the relevant authorities, and contacted the affected individuals after discovering the fraud.

Among the customers mentioned, Mark Karpelès relayed the alert on X on September 12. Here is his original post:

KYC data: confidentiality remains at the heart of the issue

The absence of stolen money does not make the disclosure trivial. The KYC (Know Your Customer, or customer due diligence) refers to the checks carried out by a bank to identify its customers. They may notably rely on an identity document and proof of address. These documents cannot be disclosed solely on the strength of an official address. The GDPR notably requires a valid legal basis, data minimization, and confidentiality.

ANSA notes that a judicial authority act, normally expected for the requests described, was allegedly missing. This point should be established by the investigation: one cannot generalize the requirement for a court order to every disclosure, but a fraudulent request does not become legitimate because it uses a government domain.

The issue therefore also concerns Revolut’s controls: who authorized the handover, on what basis, and after what checks? The public information alone does not make it possible to determine its legal responsibility.

🔎 Useful precautions, without dramatizing

For the customers concerned, it is best to check notifications in the app and be wary of messages reusing their personal information. For a company receiving a data request, the key reflex remains to verify the authority and the legal basis through an independent channel, before any transmission.