What happened
Hackers gained control of an Italian state-issued email address and used it to send emergency data requests to Revolut, according to CryptoBriefing's report Tuesday. The requests specifically targeted the fintech's crypto customers. Emergency data requests, or EDRs, are a legal shortcut law enforcement uses when it argues a delay would risk life or serious harm.
Platforms are expected to respond within hours, not days, and the process typically skips the judicial oversight that a subpoena or warrant carries. That speed is exactly what made the vector attractive. The attackers didn't need to break Revolut's own systems.
They needed a credential inside a trusted government mailbox, and that appears to be what they got. Revolut's crypto arm serves millions of European users and holds KYC data including passport scans, addresses, and transaction histories. Neither Revolut nor Italian authorities have detailed how many accounts were affected or which specific data fields were returned to the attackers.
Why it matters
EDR abuse isn't new, but it hitting a European crypto book is. US law enforcement channels were exploited the same way in 2022, when Bloomberg reported that Apple, Meta, and Discord all handed over user data to hackers posing as police. The playbook moved to Europe, and Revolut is a signal target because it straddles two regulated categories at once: a licensed EMI and a crypto asset service provider under MiCA.
Customer data pulled through this channel is more dangerous than a typical exchange leak. It carries government-verified identity documents alongside crypto activity, which is the exact combination phishing crews and SIM-swap operators pay premium prices for. It also lands during the MiCA transition window, when European CASPs are still standardising their compliance workflows and law enforcement liaison procedures.
