The neobank sector is facing a major new crisis of confidence following the disclosure of a sophisticated security breach targeting Revolut. The incident, which goes beyond a typical cyberattack, involved the hijacking of a genuine government domain to submit fraudulent data access requests. According to the company's official statement, this technical social engineering method allowed attackers to extract sensitive information without directly compromising the bank's internal infrastructure. However, subsequent revelations suggest a far more extensive operation, potentially involving European state institutions.

At the heart of the case, the hackers claim to have infiltrated the Italian police networks for a six-month period. They allegedly used this privileged access to legitimize their requests to the financial platform. The volume of stolen data is massive: the perpetrators claim to possess 147 gigabytes of documents, including internal files, personal correspondence, and agent registries. Although Italian authorities, including the National Cybersecurity Agency, have yet to confirm these claims, the precedent of ministerial accounts being hijacked to siphon data from tech giants reinforces the credibility of this state-level infiltration scenario.

The situation has taken a bizarre turn with the emergence of a digital gang war between hackers. The group known as IAmNotAVillain released a portion of the files to prove their authenticity while denouncing a former associate as an impostor. This internal rivalry has publicly exposed confidential information belonging to thousands of customers, primarily located in Switzerland and France, but extending to over a dozen European countries. The leaks include identity verification documents, KYC selfies, and full Bitcoin transaction histories. Public figures, ranging from high-profile athletes to entrepreneurs, are among the identified victims, illustrating the targeted nature of some of the extractions.

The implications of this breach are multifaceted and raise critical questions regarding the security of communication protocols between the public and private sectors. Beyond the exorbitant ransom demand of 10,000 bitcoins issued to the firm's leadership, it is the integrity of administrative communications that is now in question. If the compromise of law enforcement systems is confirmed, it would demonstrate a systemic vulnerability where the trust placed in official domains becomes the weakest link in the cybersecurity chain. For users, the risk of fraud and identity theft is now a long-term reality, forcing financial institutions to completely rethink their external request validation processes.