Italy Files: the breach behind the fake police request that unlocked Revolut data
On 25 September the actor calling itself IAmNotAVillain began publishing samples of what it labels "the Italy files" on a Tor site: a folder it says holds more than 85,000 files and over 150 GB taken from Italian law enforcement and ministry systems. Among the previews are diplomatic passports, police personnel records, port access authorisations and institutional certified-email correspondence.
That publication supplies the missing first half of a story we ran two weeks ago, when Revolut disclosed customer passports, selfies and transaction histories in response to a request from a government agency that turned out to be forged. The forgery worked because the mailbox it came from was real.
In short
- Samples only: the group claims roughly 147 to 150 GB and six months of access, none of which Italian authorities have confirmed.
- The Revolut disclosure was obtained with fraudulent European Investigation Orders sent from a compromised certified mailbox on an interior ministry domain.
- About 680 Revolut customers were affected; the bank says its own systems were not breached, and on the evidence so far that is accurate.
- The prosecutor's office in Reggio Calabria is investigating. The group first demanded three million dollars from Revolut.
What is claimed and what is established
Reporting on leaks of this kind tends to collapse the distinction between a criminal's press release and a verified fact. The distinction is worth keeping, because almost everything about the volume comes from the person who wants it to sound large.
| Claim | Standing |
|---|---|
| 147 to 150 GB, more than 85,000 files | Asserted by the group; only samples are online, the bulk is not downloadable |
| Data on more than 130,000 officials | Asserted; no independent count |
| Six months of access to law enforcement systems | Asserted; not confirmed by Italian authorities |
| Samples include diplomatic passports, police files, visa clearances | Visible in the published previews and described by several Italian security outlets |
| A compromised certified mailbox was used against Revolut | Documented in the Revolut disclosure and its reporting |
| Around 680 Revolut customers affected | Reported figure tied to the disclosure |
The Italian interior ministry had said publicly that no law enforcement or ministry data was compromised beyond the Revolut customer information. After the samples appeared, the MP Giulia Pastorella said that if their authenticity were confirmed the matter would be of unprecedented gravity. That disagreement is currently the story.
How a real mailbox forges a real request
The mechanism is worth spelling out, because it is not a hack of a bank. Italy uses PEC, a certified email system with legal standing. A PEC account at the Prefecture of Reggio Calabria, on an interior ministry domain, was compromised. From that address the attacker sent what looked like European Investigation Orders, the standard cross-border instrument for obtaining evidence, containing batches of cryptocurrency transaction identifiers.
Nothing had to be broken at Revolut. The request arrived from a government domain with the right paperwork attached, and a compliance team did what compliance teams are built to do. We described the outcome at the time: the request was fake, the data was real. Days later a second incident surfaced through the broker DriveWealth, which we also covered.
Why this is an industry problem, not an Italian one
Every large platform has a channel for law enforcement requests, and every one of them ultimately authenticates the sender by the domain the mail came from plus a document that looks correct. That was a reasonable design when forging a government mailbox meant forging a government mailbox. It is a weak design once a mailbox can simply be stolen, and it fails in exactly the direction that matters: it fails open, handing over data rather than refusing it.
The published files make the next round cheaper. Identity documents and personal details of officials are precisely what you need to make the following forged request more convincing, which is why a leak of civil servants' paperwork embarrasses the civil servants least of all. It is inventory.
What a reader can actually do
Very little, and it is worth being honest about that rather than attaching advice that does not fit. No setting on your phone governs whether a bank believes an email from a prefecture. A VPN is irrelevant here; the disclosure happened between two institutions, nowhere near your connection.
What the case does argue for is caution about how much verification material any one service holds. Revolut's compliance file existed because identity checks require it, and the same file is what left the building. That is the uncomfortable logic behind our piece on the bank launching face payments two weeks after the disclosure: the enrolment selfie is useful precisely because it is hard to fake, and valuable to an attacker for the same reason.