Hackers breached an Italian government email account and used it to impersonate police, then requested Revolut customer data on high-value "crypto whale" accounts, according to a Cointelegraph report citing the Financial Times, posted September 16, 2026. The demand did not arrive on forged letterhead from an outside address. It came from inside a real state mailbox, which is what made it hard to reject.
That detail sharpens a story Revolut users already saw a version of last week, when the company handed over KYC files and Bitcoin histories to a spoofed request. The earlier alert described the method in general terms. The FT reporting names the mechanism: a compromised government account gave the attackers a sender address that passed the smell test, and the police framing added urgency that discouraged a second look.
A trusted sender is the whole exploit
Emergency data requests are a standard channel between platforms and law enforcement. A police force investigating fraud or laundering can ask a fintech for account records, and the platform is expected to respond, often quickly, sometimes before a formal warrant clears. The system runs on the assumption that a request from a genuine government domain is genuine. Break that assumption and the entire process inverts. The attacker no longer needs to forge anything convincingly, because the trust is attached to the mailbox, not to the person typing.
Breaching a single government email account is a smaller task than breaching Revolut itself. Public-sector mail systems vary widely in security, and one reused password or phished credential is enough. Once inside, the attacker inherits the account's standing. To an intake team processing dozens of law-enforcement demands, a message from a real ministry address carrying a police reference reads as routine work, not as a threat.
The targeting was selective, not a bulk dump
The reporting points to "crypto whale" accounts as the object of the request, which changes the shape of the risk. This was not an indiscriminate scrape of the full customer base. It was a search for individuals holding large balances, the people for whom a de-anonymized identity carries the highest consequences.
A Revolut record on such a user can tie a legal name, address, and verification documents to observed crypto activity. Stripped of pseudonymity, a large holder becomes a concrete target for extortion, SIM-swap attempts, phishing built on real transaction details, or physical coercion. The value of the data is not that it is secret in the abstract. It is that it points attackers at specific wealthy people and tells them roughly what those people control.
That concentration is the recurring cost of custodial convenience. When one company holds both your identity and a window into your balances, a single failure at that company exposes the link. Spending from your own wallet through self-custody options does not remove identity checks at a card issuer, but it limits how much any one leaked record can reveal about your total holdings. The narrower reason some users seek minimal-verification products is the same one on display here: fewer copies of your dossier, fewer places for it to leak.
The verification layer keeps failing before the code does
None of this required defeating Revolut's cryptography or its infrastructure. The company, headquartered in the United Kingdom and serving tens of millions of accounts, met its usual technical bar. The gap was procedural: no independent step to confirm that a request from a government address actually came from the person it claimed, and no callback to a known official channel before releasing sensitive records.
Regulators have started to treat this human layer as the real front line. The EU's 24-hour rule now forces wallet makers to report exploits fast, a recognition that response speed matters when an attack is already moving. The Bank for International Settlements has warned that AI is compressing the exploitation window from weeks to minutes, which makes plausible impersonation cheaper to produce and faster to deploy. A hijacked government inbox is the low-tech version of the same problem: the attacker borrows credibility rather than building it.
For users, the practical read is unchanged from last week and reinforced. Treat identity documents already submitted to any platform as permanently exposed, because they cannot be reissued. Assume that any message referencing your real balances or ID details is a phishing attempt using leaked context. Where a service supports hardware-key or passkey login, use it, since knowing who you are does not help an attacker who still needs a physical key.
Overview
Hackers breached an Italian government email account and posed as police to request Revolut data on high-value crypto holders, per a Cointelegraph report citing the FT on September 16, 2026. The exploit was the trusted sender, not any technical break: a real state mailbox lent the fraudulent request authority Revolut's intake process did not independently verify. The selective focus on large accounts raises the stakes for those users, whose identities can now be mapped to their on-chain wealth. The failure sits in the human verification layer, the same weak point behind a string of recent incidents, and the durable defense is holding fewer copies of your identity in fewer custodial hands.



