Threat Intelligence Brief
Curated summary with source attribution
Source: it-connect.tech
Threat Risk: High
Victim: Revolut and Italian Law Enforcement
Incident: Data breach via impersonation of government authorities leading to PII theft and extortion.
Impact: Exposure of passports, transaction histories, and personal data for high-profile clients across approximately 30 countries.
Attacker: IAmNotAVillain
Analysis: Threat actors leveraged a compromised or spoofed government email domain to trick Revolut into releasing sensitive customer PII. The attacker, ‘IAmNotAVillain,’ claims a deeper intrusion into Italian police infrastructure was used to facilitate the fraud. This represents a high-impact attack where a trusted authority is weaponized to bypass corporate security controls.
Recommendations: Implement multi-channel verification for all government data requests to move beyond reliance on email domains; Enhance monitoring for anomalous outbound data transfers to external agencies; Audit and harden government-facing communication channels against account takeover
Source: IT-Connect
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source