Risk Radar

/ high

Revolut / Italian PEC: Alleged trust-channel data exposure

Hackers claim Italian certified-email access was abused to obtain data on \~680 Revolut customers; Revolut says internal systems were not breached.

September 16, 2026Last updated 10:30 UTC2 min read

What happened

Hackers claim Italian certified-email access was abused to obtain data on \~680 Revolut customers; Revolut says internal systems were not breached.

Confirmed facts and boundaries

CEXVia separates confirmed official facts from allegations, media reporting and adjacent entities. The event is not expanded beyond the evidence status stated above.

Why it matters

This development changes the operational, regulatory, enforcement or security risk profile for users and market participants. It is significant enough to track independently rather than burying it in a short news summary.

Timeline

  • September 15--16: Current status verified for this report.
  • Next milestone: Follow the event-specific deadlines, court

process, legislative process or official incident update.

Evidence Status

Media / Developing. Claims that are not officially adjudicated or independently confirmed remain Developing.

Risk Assessment

High. The rating reflects potential user, market, compliance or data-security impact; it does not convert allegations into confirmed findings.

What to Watch Next

Official updates, deadline execution, court or legislative status, user impact, asset restrictions and any material correction to the current facts.

FAQ

Is this event confirmed?

The core event is supported at the evidence level stated above. \### Are allegations treated as facts? No. ### Can the risk rating change? Yes, as execution, recovery, court, legislative or incident facts change. \### Are adjacent companies automatically implicated? No. Entity boundaries are maintained. \### Will CEXVia update this URL? Yes. Material developments should update this existing /risk/ URL rather than create a duplicate.