Italian Probe into Government Email Hack Linked to Financial Data Breach
Italian cybercrime police have launched an investigation into a breach of government email accounts, which is suspected to be connected to the unauthorized acquisition of customer data from the fintech firm Revolut. The investigation centers on allegations of illegal access to computer systems and potential computer fraud.
The Breach Chain: From Data Leak to Suspected Government Account Misuse
Preliminary findings suggest that hackers gained control of one or more government email accounts. The attackers then allegedly used the compromised accounts to submit data requests to Revolut, thereby obtaining sensitive customer information. This tactic transformed a third-party data leak into a more complex case involving government system security.
Some local media reports initially pointed to email accounts belonging to the Reggio Calabria provincial government. However, the institution later issued a statement firmly denying it had ever sent any data request to Revolut, distancing itself from the alleged unauthorized access.
Stakeholder Responses and Investigation Status
Revolut addressed the situation with measured statements. A company spokesperson declined to publicly identify the specific government agency involved but confirmed that Revolut had proactively reported the incident to the relevant Italian authorities and pledged full cooperation with the ongoing investigation.
Importantly, Revolut assured its users that its core operating systems, internal databases, and customer funds remained secure and were not compromised in this incident. The data access appears to have been achieved through the fraudulent use of externally compromised accounts.
Security Implications and Broader Concerns
This incident highlights several critical security vulnerabilities:
- Supply Chain Attack Risks: The security of a company's customer data can be threatened not only by its own defenses but also by vulnerabilities in the systems of partners or associated organizations.
- Authentication Weaknesses: The fact that attackers used stolen government email credentials suggests potential flaws in the verification processes for authenticating data requestors.
- The Need for Coordinated Response: The case, straddling private-sector data security and public-sector system intrusion, requires close collaboration between law enforcement, government agencies, and the affected company to unravel.
The investigation by Italian cybercrime police is ongoing. The final classification of the incident, assignment of responsibility, and any remedial measures for affected customers await the official findings.