
Revolut Case: Compromised Institutional PEC Used for Social Engineering Attack
hacker attacksmalwarelatest newsCISOsecurity awarenesssocial engineering
The Revolut case demonstrates how a compromised institutional PEC (Posta Elettronica Certificata - certified email) account was used as a social engineering tool. The incident shows that a communication channel traditionally considered secure in Italy was exploited by attackers. The compromise transformed the certified email system into a vector for social engineering attacks, exploiting the trust associated with institutional PEC communications. The case highlights that certifications and standard procedures were insufficient to prevent the attack, as the authority and perceived legitimacy of the compromised PEC channel enabled the social engineering attempt.