Fintech company Revolut has confirmed that a social engineering attack, reportedly originating from compromised Italian government email accounts, resulted in the exposure of sensitive data for hundreds of customers. The incident highlights an escalating cybersecurity threat: institutional communication channels designed to establish trust are now being weaponized against regulated financial firms.
According to a Security Affairs report, the attackers did not breach Revolut's internal systems directly. Instead, they are suspected of having gained access to Italian government Posta Elettronica Certificata (PEC) accounts — a certified email system used for official legal and administrative communications that carry legal weight in Italy. Using these highly credible channels, the threat actors allegedly impersonated law enforcement and pressured Revolut into disclosing customer data.
Revolut emphasized that its core infrastructure remained uncompromised. The company stated that the data disclosure resulted from compliance with what appeared to be legitimate legal requests from an authoritative source.
The incident exposes a critical and systemic vulnerability in global compliance and security protocols. Regulated financial institutions are often legally obligated to respond to official data requests from law enforcement. The attack exploited the inherent trust asymmetry in this process: when communication arrives via a certified, legitimate government email system, distinguishing it from a genuine inquiry becomes exceedingly difficult without secondary, out-of-band verification.
The compromise of a single high-privilege institutional credential — in this case, an Italian government PEC account — creates a significant blast radius. It demonstrates how attackers can leverage systemic trust in one institution to compromise the data security of another, even one with robust cybersecurity defences.
For financial technology companies and corporate security teams, particularly in regions with dense cross-border data flows such as Hong Kong, the incident serves as a cautionary example. Analysts note that security must extend beyond internal network defences to encompass rigorous verification procedures for high-impact external requests. Industry observers point to the need for pre-agreed communication channels with law enforcement and formalized protocols that allow staff to challenge requests from authoritative sources without fear of reprisal.
The investigation into the broader Italian government infrastructure compromise remains ongoing.
title: "Revolut數據泄露或源於遭入侵的意大利政府電郵帳戶" date: 2026-09-16T14:24:00 author: HKLUG Team source_url: https://securityaffairs.com/199180/data-breach/revolut-data-leak-may-trace-back-to-compromised-italian-government-accounts.html tags: [data-breach, social-engineering, fintech, cybersecurity]
金融科技公司Revolut證實,一宗據報源自遭入侵意大利政府電郵帳戶的社會工程攻擊,導致數百名客戶的敏感資料外洩。事件凸顯了日益嚴峻的網絡安全威脅:原本用於建立信任的機構溝通渠道,正被惡意者武器化,針對受監管的金融機構。
據Security Affairs報道,攻擊者並未直接入侵Revolut的內部系統。相反,他們懷疑取得了意大利政府「認證電子郵箱」(Posta Elettronica Certificata, PEC)帳戶的存取權限。PEC是意大利用於處理具法律效力的官方及行政通訊的認證電郵系統。透過這些極具公信力的渠道,威脅者據報冒充執法人員,向Revolut施壓要求提供客戶資料。
Revolut強調其核心基礎設施未被入侵。公司表示,資料外洩源於遵循了看似來自權威機構的合法法律要求。
事件暴露了全球合規與安全協議中一個關鍵且系統性的漏洞。受監管的金融機構通常在法律上有義務回應執法部門的官方資料請求。此次攻擊利用的正是這一流程中固有的信任不對稱性:當通訊來自經認證的合法政府電郵系統時,若不透過次要的帶外驗證方式,極難將其與真正的查詢區分。
單個高權限機構憑證(本案中為意大利政府PEC帳戶)的洩露,產生巨大的爆炸半徑。它表明攻擊者可以利用對一個機構的系統性信任,去破壞另一個機構(即便其擁有強大網絡安全防禦)的資料安全。
對於金融科技公司及企業安全團隊,尤其是在香港這樣跨境資料流密集的地區,事件是一個警示。分析指出,安全防線必須超越內部網絡防禦,擴展至對高風險外部請求的嚴格驗證流程。業界觀察認為,有必要與執法機構建立事先約定的溝通渠道,並制定正式協議,讓員工可以質疑來自權威來源的請求而不必擔心報復。
針對更大範圍意大利政府基礎設施入侵事件的調查仍在進行中。
金融科技公司Revolut已證實,一宗據報源自遭入侵意大利政府電郵賬戶的社會工程攻擊,導致數百名客戶的敏感數據外洩。該事件突顯了一項日益嚴峻的網絡安全威脅:原本用於建立信任的機構通信渠道,正被武器化用以對付受監管的金融機構。
據Security Affairs報道,攻擊者並未直接入侵Revolut的內部系統。相反,他們疑已取得意大利政府「認證電子郵箱」(Posta Elettronica Certificata,簡稱PEC)賬戶的存取權限——該系統在意大利用於處理具法律效力的官方及行政通信。利用這些高度可信的渠道,有關威脅者據報冒充執法人員,向Revolut施壓以披露客戶數據。
Revolut強調其核心基礎設施未被入侵。該公司表示,數據洩露源於其遵從了看似來自權威來源的合法法律請求。
此事件暴露了全球合規與安全協議中一個關鍵且系統性的漏洞。受監管的金融機構通常在法律上有義務回應執法部門的官方數據請求。該攻擊利用了此流程中固有的信任不對稱性:當通信來自經認證的合法政府電郵系統時,若缺乏次要的帶外驗證機制,幾乎難以將其與真實查詢區分。
單個高權限機構憑證——本案中為意大利政府PEC賬戶——的洩露,造成巨大的影響範圍。這表明攻擊者可利用對某一機構的系統性信任,破壞另一機構的數據安全,即使後者具備穩健的網絡安全防禦。
對金融科技公司及企業安全團隊而言,尤其在香港這類跨境數據流密集的地區,此事件構成警示。分析人士指出,安全防禦必須超越內部網絡防禦,涵蓋對高影響外部請求的嚴格驗證程序。業內觀察者認為有必要建立與執法部門預先約定的通信渠道,並設立正式協議,讓員工可以在無須擔心報復的情況下,對來自權威來源的請求提出質疑。
針對更大範圍意大利政府基礎設施遭入侵事件的調查仍在進行中。
