Revolut: initial investigations do not confirm the theft of 147 gigabytes of data from the Ministry of the Interior
Initial findings by the Postal Police suggest that no information has been leaked from the Home Office’s systems
So far, the Postal Police have reportedly found no security breaches in the Interior Ministry’s systems. Initial findings do not appear to confirm the theft of 147 gigabytes of law enforcement material – including internal documents and conversations between officers – claimed by the hacker collective “I am not a villain”. The investigations began with the Revolut scam: the group had obtained the confidential data of 680 customers via a request that appeared to originate from the certified email account of the Ministry of the Interior’s Reggio Calabria Prefecture. The scam targeting the bank was successful. The theft from the Ministry’s archives, however, remains to be proven.
The investigation by the Reggio Calabria Public Prosecutor’s Office is stepping up its scrutiny. Investigators from the Postal Police Unit, headed by Ivano Gabrielli, are monitoring the systems: as things stand, no data appears to have been stolen from the Home Office’s network. This is a preliminary finding, not a definitive conclusion. A definitive conclusion will require the investigations to be completed.
The investigations stem from data that Revolut – a British financial firm operating in Europe via a Lithuanian bank – handed over to the hackers, believing they were responding to the Home Office. The collective obtained confidential documents and information on customers residing mainly in France and Switzerland, but also in 31 other countries.
From that delivery, the investigation must trace the request back to its source. Did the hackers breach a certified email account belonging to the ministry, or did they merely forge the address? This is the first issue to be resolved: establishing whether the cybercriminals were in control of an official account or had simply faked its origin. The fact that the scam on the bank was successful does not prove that the 147 gigabytes of law enforcement material were also stolen. It is this separate claim for which, so far, there appears to be no evidence.
The National Cybersecurity Agency is also monitoring the case within the limits of its remit. Revolut is not one of the entities subject to the obligations under the NIS 2 Regulation and would therefore not be required to make the relevant notifications to the ACN. A special regime also applies to the Ministry of the Interior: the Ministry’s infrastructure is not subject to direct monitoring by the Agency. Its security is ensured through the Internal CERT.

