Italy Files: the breach behind the fake police request that unlocked Revolut data

26.09.2026 6 min 35

On 25 September the actor calling itself IAmNotAVillain began publishing samples of what it labels "the Italy files" on a Tor site: a folder it says holds more than 85,000 files and over 150 GB taken from Italian law enforcement and ministry systems. Among the previews are diplomatic passports, police personnel records, port access authorisations and institutional certified-email correspondence.

That publication supplies the missing first half of a story we ran two weeks ago, when Revolut disclosed customer passports, selfies and transaction histories in response to a request from a government agency that turned out to be forged. The forgery worked because the mailbox it came from was real.

In short

  • Samples only: the group claims roughly 147 to 150 GB and six months of access, none of which Italian authorities have confirmed.
  • The Revolut disclosure was obtained with fraudulent European Investigation Orders sent from a compromised certified mailbox on an interior ministry domain.
  • About 680 Revolut customers were affected; the bank says its own systems were not breached, and on the evidence so far that is accurate.
  • The prosecutor's office in Reggio Calabria is investigating. The group first demanded three million dollars from Revolut.

What is claimed and what is established

Reporting on leaks of this kind tends to collapse the distinction between a criminal's press release and a verified fact. The distinction is worth keeping, because almost everything about the volume comes from the person who wants it to sound large.

ClaimStanding
147 to 150 GB, more than 85,000 filesAsserted by the group; only samples are online, the bulk is not downloadable
Data on more than 130,000 officialsAsserted; no independent count
Six months of access to law enforcement systemsAsserted; not confirmed by Italian authorities
Samples include diplomatic passports, police files, visa clearancesVisible in the published previews and described by several Italian security outlets
A compromised certified mailbox was used against RevolutDocumented in the Revolut disclosure and its reporting
Around 680 Revolut customers affectedReported figure tied to the disclosure

The Italian interior ministry had said publicly that no law enforcement or ministry data was compromised beyond the Revolut customer information. After the samples appeared, the MP Giulia Pastorella said that if their authenticity were confirmed the matter would be of unprecedented gravity. That disagreement is currently the story.

How a real mailbox forges a real request

The mechanism is worth spelling out, because it is not a hack of a bank. Italy uses PEC, a certified email system with legal standing. A PEC account at the Prefecture of Reggio Calabria, on an interior ministry domain, was compromised. From that address the attacker sent what looked like European Investigation Orders, the standard cross-border instrument for obtaining evidence, containing batches of cryptocurrency transaction identifiers.

Nothing had to be broken at Revolut. The request arrived from a government domain with the right paperwork attached, and a compliance team did what compliance teams are built to do. We described the outcome at the time: the request was fake, the data was real. Days later a second incident surfaced through the broker DriveWealth, which we also covered.

Why this is an industry problem, not an Italian one

Every large platform has a channel for law enforcement requests, and every one of them ultimately authenticates the sender by the domain the mail came from plus a document that looks correct. That was a reasonable design when forging a government mailbox meant forging a government mailbox. It is a weak design once a mailbox can simply be stolen, and it fails in exactly the direction that matters: it fails open, handing over data rather than refusing it.

The published files make the next round cheaper. Identity documents and personal details of officials are precisely what you need to make the following forged request more convincing, which is why a leak of civil servants' paperwork embarrasses the civil servants least of all. It is inventory.

What a reader can actually do

Very little, and it is worth being honest about that rather than attaching advice that does not fit. No setting on your phone governs whether a bank believes an email from a prefecture. A VPN is irrelevant here; the disclosure happened between two institutions, nowhere near your connection.

What the case does argue for is caution about how much verification material any one service holds. Revolut's compliance file existed because identity checks require it, and the same file is what left the building. That is the uncomfortable logic behind our piece on the bank launching face payments two weeks after the disclosure: the enrolment selfie is useful precisely because it is hard to fake, and valuable to an attacker for the same reason.

Was Revolut hacked?
No, and that is the point. The bank says its systems were not breached and the available evidence supports that. The data left through a legitimate process that was fed a forged request.
Is the Italian leak confirmed?
Not independently. Samples are published and have been examined by Italian security outlets, but the total volume, the file count and the six months of access are claims by the group. Italian authorities have not confirmed them.
Why would anyone want officials' passports?
To impersonate them. Identity documents and internal correspondence are the raw material for the next fraudulent request, which is the same technique that produced the Revolut disclosure.
Could this happen outside Italy?
The mechanism is not Italian. Any jurisdiction where a platform authenticates a law enforcement request by sender domain and attached paperwork has the same exposure; Italy simply has a formal certified-mail system that made the trust explicit.
Would a VPN have protected the affected customers?
No. The data moved from the bank to a party impersonating the police. Nothing about the customer's own connection was involved.

italyrevolutdata leakpersonal dataprivacypolicebanksidentity theftsocial engineeringdark webcybersecurityfintech

Read also