The Revolut case has reached a precise new checkpoint: for the first time, an Italian institutional body has independently verified a specific element of the breach on Italian soil, moving the story beyond attacker claims alone. On September 18, responding to an urgent parliamentary question, Deputy Interior Minister Wanda Ferro disclosed the findings of a review conducted by Italy's National Cybersecurity Agency (ACN): 8 of 680 affected clients are Italian, and a certified email (PEC) address linked to the Prefecture of Reggio Calabria has been confirmed as compromised, according to the parliamentary statement recorded by the Italian Senate on Act No. 3-02788. This update marks a clear status change in the Revolut PEC Italy breach story, and it demands the same editorial discipline applied throughout.
The most important clarification comes first: this confirmation covers one specific, bounded element. It does not confirm, and must not be conflated with, the far broader claims made by the attacker in recent days, including an alleged six-month compromise of multiple Italian law enforcement departments and 147 gigabytes of extracted material. That part of the story remains, as of today, unconfirmed by Italian authorities.
What the Government Told Parliament
According to Deputy Minister Ferro's parliamentary statement, Italy's National Cybersecurity Agency was notified by Revolut on September 12 of a possible security incident. On September 15, the company formally confirmed the data breach, stating it had shared data relating to 680 clients in total, 8 of them Italian, and had already notified the individuals directly. Revolut also flagged the compromise of a certified email address belonging to the Prefecture of Reggio Calabria.
One technical detail deserves attention. CSIRT Italia, the ACN's incident response team, confirmed the compromise not through an independent investigation of Prefecture systems, but by analysing a sample of one fraudulent email provided by Revolut itself, the kind attackers used to submit information requests. The verification is real, but its methodology is specific: it rests on evidence supplied by the victimised company, not on a concluded autonomous audit of public administration infrastructure.

The Legal Detail That Explains the Path Taken
A regulatory nuance buried in the parliamentary response helps explain why this case travelled through political channels rather than standard compliance procedures. Revolut, as a UK-incorporated entity, falls outside the scope of Italian and EU network security obligations under the NIS Directive, meaning it was not required to make formal notifications to the national agency through the ordinary procedure applicable to companies under that jurisdiction. This is why the information reached Italian authorities through informal channels, and why the matter ended up debated directly in Parliament rather than following the standard technical and bureaucratic route.
Ferro confirmed that investigations remain ongoing. ACN is engaged in continuous dialogue with Revolut to deepen the picture, while also cooperating with the Interior Ministry on threat mitigation. The Postal Police and the National Anti-Mafia and Anti-Terrorism Directorate are also involved, which signals the institutional weight placed on this case, even as official confirmations remain limited to a single compromised address.
Confirmed vs Still Claimed, Updated
What changes after the September 18 update. Source: parliamentary statement, ACN/CSIRT Italia, 2026
- Now confirmed: 8 Italian clients out of 680; the PEC address of the Reggio Calabria Prefecture compromised.
- Still claimed, not confirmed: multiple law enforcement departments, 147 GB of data, six months of access.
- Still open: investigations continue, no definitive conclusions announced.
Banca d'Italia Is Watching Too
Completing the institutional picture, on September 19 sources attributed to Banca d'Italia stated the central bank is closely monitoring developments. Brief as it is, that intervention confirms the case is now tracked at multiple levels of Italy's institutional apparatus, from cybersecurity to financial supervision. The implication is that the consequences are considered significant well beyond the single security incident itself.

Why the Distinction Still Matters
This point was central to every previous update, and it's even more pressing now that part of the story has received official backing. Today's verification covers a single certified email address, identified through analysis of a sample provided by Revolut. It does not extend to, and cannot be read as endorsing, the far larger claims made by whoever took responsibility for the attack: multiple Italian law enforcement departments compromised over six months, with 147 gigabytes of extracted material, as detailed in our previous update covering those claims.
Italian authorities have not confirmed that broader narrative. One confirmed PEC address is not indirect validation of the entire attacker story. These remain two separate planes, and treating them as one would be a journalistic error, and potentially unfair to the institutions involved, before ongoing investigations reach their conclusions.
The Larger Picture
This update, limited in its concrete scope, nonetheless marks a meaningful milestone in a story we began covering with the initial account of the fake government request that deceived Revolut. For the first time, a specific element of the Italian dimension of the case moves out of the realm of unverified claims and receives institutional confirmation, however indirect the verification methodology: a company-supplied sample rather than an independent audit of public administration systems.
The lesson for anyone following cybersecurity incidents of this complexity is consistent with every previous chapter: truth surfaces in stages. Partial confirmations arrive at different moments and must be handled with equal rigour at each step, never stretched to validate a wider narrative they do not actually support. We will continue to cover developments using the same method, updating the reconstruction only when new verifiable confirmations emerge, and keeping clearly separate what we know for certain from what remains, for now, an unconfirmed claim.


