Hackers pretend to be Italian authorities and obtain Revolut customer data via PEC: how to defend yourself

Nearly seven hundred account holders (as estimated by the Financial Times at 680) were exposed without anyone having forced a lock. This is what happened to the British giant Revolut, which started as a young digital payments company and grew to undermine the continent’s large credit institutions. Passports, home addresses, account details and transaction history have ended up in the hands of a group of cyber criminals, in what is called a data breach. The point is that Revolut did not suffer an intrusion into its servers, but fell for a scam.

In fact, according to what the authors of the robbery themselves said, the lock pick would have been a certified email address belonging to the Italian police force, compromised at a previous time and then reused as a pass. From that address a formal request for data delivery was made, motivated by the urgency of an investigation (which in reality did not exist), a request which passed the authentication checks and initially did not arouse suspicion. Subsequently, the exchange of emails continued until the company contacted the Italian institution directly, which denied ever having sent those messages. The Postal Police is now investigating.

What happened to Revolut

The company, the largest European fintech group, with over 80 million users, of which approximately 5 million are Italian, issued a statement in which it explained that it had “identified a sophisticated external impersonation scam, in which an unauthorized third party used an email with a legitimate domain of a government agency to send fraudulent requests for information. Upon detection we immediately blocked the address and notified the relevant government agency, law enforcement, data protection authorities data and financial regulators. Revolut systems and customer funds were not affected.”

According to the company, the people involved would be very limited in number, with the Financial Times speaking of around 680 customers contacted, a figure that Revolut did not want to confirm. The Italian Postal Police are now working on the episode, for abusive access and computer fraud, and the British Information Commissioner’s Office, which opened an investigation on 15 September after the company’s spontaneous report.

How the PEC scam was built

The data breach it would have been claimed by the hacker group IAmNotAVillain and to understand how the deception managed to seem credible we must start from when it all began, six months ago. The cyber criminals said that it all started with the violation of a PEC mailbox of the Ministry of the Interior, documented with screenshots of the message headers. 147 gigabytes of documents, diaries and personal data would have been stolen from there. That address was then used to send a request for customer information to Revolut’s Lithuanian headquarters, motivated by an investigation attributed to the Milan prosecutor’s office.

The gateway would have been an infostealer, malware designed to collect and exfiltrate sensitive information from compromised devices. The hacker then took possession of the credentials to access the email account of a government employee and then created a fake European Investigation Order with which to demand Revolut hand over the information. The technique falls into the category of Man in the Maila mechanism through which a criminal inserts himself into an already active mailbox and, from that location, carries on correspondence by pretending to be the legitimate owner.

How to defend yourself and what to do

In the space of a few years, infostealers have become a leading weapon in the cybercrime arsenal. The National Cybersecurity Agency, in its report, identifies some concrete countermeasures to strengthen defenses against a threat that is constantly changing.

A first measure is multi-factor authentication (MFA), which must be activated on each account. The rule also applies not to open links or attachments contained in unexpected or out of the ordinary messages. In case of doubt, the right way is to check the validity of the communication on the organisation’s official channels or contact its institutional contact details directly. Systems and devices must always be kept aligned with the latest available versions, installing patches and security updates as soon as they are released.

It is also advisable to disable the automatic saving of passwords in browsers, instead relying on a dedicated manager, with an encrypted database and created by a proven reliable manufacturer. It remains essential for companies to regularly organize training and raise awareness of staff on IT risks and the good practices to be adopted.

In the coming weeks it is prudent to look with suspicion at any unexpected contact, each message must be verified by accessing the official app or calling the numbers published on institutional channels, never those indicated in the communication received. It is also a good idea to carefully monitor your account movements, activate two-factor authentication on all financial services and replace passwords that are reused across multiple platforms.