Leggi in italiano
Current Affairs

They asked Revolut for 680 customers’ data using a stolen PEC address, and the bank handed it over: a lesson for San Marino too

A stolen certified email address, five months of exchanges, and a data breach that exposes the everyday mistakes we all make online.

The case explains, better than any training course could, why cybersecurity almost always breaks down over trust.

For months, cybercriminals asked Revolut, the digital bank with millions of customers across Europe, for the confidential data of hundreds of account holders.

And Revolut gave it to them. That’s it.

Identity documents, passports, account information, cryptocurrency transactions: 680 people affected, eight of them Italian. No attack on the bank’s systems whatsoever.

The requests came from a genuine certified email (PEC) address — that of the Prefecture of Reggio Calabria — which had fallen into the wrong hands.

A comedy in several acts. The requests were signed “Polizia postale” (Italy’s postal and cybercrime police), which in fact has its own official channels and does not write from prefecture mailboxes.

There was no judicial order attached, something that normally accompanies requests of this kind.

And yet the exchange went on for around five months. At one point the bank even explained to the fraudsters how to correct the heading of their request so it would be filled in properly. In another email, it apologised for the delay in sending the data. Then in July it sent everything, with the password to open the files dispatched in a separate email.

To the same address.

The ending is no laughing matter.

The group claiming responsibility for the attack demanded a three-million-dollar ransom in cryptocurrency from the bank, threatening to sell the data otherwise. The Reggio Calabria public prosecutor’s office and the postal police are investigating, and Italy’s data protection authority has launched checks on Italian banks. Revolut describes it as a “sophisticated impersonation scam”.

Sophisticated only up to a point: nobody forced a door open. Someone opened it themselves, because whoever was knocking had the right stamp on the paperwork.

The things we take for granted in San Marino

Lounging under a beach umbrella, it’s tempting to think this is a story about faraway banks.

Instead, it contains almost every mistake we make every day, here included.

“If it comes from an official address, it’s genuine.”

That’s the heart of the Revolut case. An institutional address, a certified email, an organisation’s logo, an official’s signature: all of this tells you where a message came from, not who actually wrote it. Mailboxes get stolen, and a stolen mailbox is the most convincing of all.

The rule is simple: if a request seems unusual, verify it with a phone call to a number you already know, not the one written in the email.

“We all know each other here.”

That’s San Marino’s strength — and also its digital weakness.

A message that looks like it’s from the accountant, a cousin at the bank, or a public office is taken at face value without a second thought. Fraudsters know this, and in a small country, impersonating someone familiar is easier, not harder.

“Why would anyone want to attack us?”

Nobody picks San Marino off a map. Criminals try thousands of addresses and passwords at random, and stop wherever the door gives way. You don’t need to be an important target — just an easy one.

“I’ll send the password separately, that way it’s safe.” That’s exactly what Revolut did. Sending a password in a second email to the same recipient protects nothing: if the mailbox is in the wrong hands, the password ends up there too. If it really must be shared, do it over the phone or through a different channel altogether.

“I’ve used the same password for years, I remember it.”

When any website suffers a data breach, the stolen passwords are automatically tried everywhere else: email, banking, company systems.

A recycled password turns some distant website’s problem into your own. Different passwords for every service, a password manager to keep track of them, and above all, two-factor verification with a code sent to your phone: on its own, this stops the vast majority of these thefts.

The lesson of the summer

The Revolut case doesn’t teach us that technology is fragile.

It teaches us that security almost always breaks down at the exact point where a person trusts without verifying. A bank with thousands of employees and advanced systems was brought down by a well-written email.

A twenty-person company, or a family, can be brought down by far less.

The good news is that the most effective defences cost nothing: one extra phone call, a different password, a code on your phone.

And a bit of healthy Sammarinese suspicion — the kind we usually reserve for our neighbours, but which is worth keeping for incoming mail as well.

Hanno chiesto a Revolut i dati di 680 clienti con una PEC rubata, e la banca glieli ha mandati: la lezione vale anche per San Marino