Economy
the interview •
Pastorella (Azione): “The Home Office must take responsibility for the Revolut case”
The cyberattack on the digital bank and the Home Office’s response regarding the eight Italian customers affected. “From the undersecretary’s words, it did not seem to me that there was any intention to find out what had happened, nor, indeed, to put things right,” says the MP

“The Home Office must take responsibility for the Revolut case. Attacks via certified email have almost doubled in Italy.” Giulia Pastorella, an MP for Azione, was not convinced by the Home Office’s response (via Undersecretary Wanda Ferro) to the urgent parliamentary question she had drafted to request information on the matter. As she explains to Il Foglio, the basis of her inquiry is “the alleged compromise of certain certified email addresses at the Ministry of the Interior”. This is a point on which Ferro did not dwell at length, stating instead that amongst the data of the 680 customers provided by the British digital bank – which had been passed on to cybercriminals – there were details of “only” 8 Italians. “This is a case of applying double standards,” says Pastorella. “When it comes to private companies, people are quick to accuse them of carelessness, a lack of protocols, and so on. When it comes to the public sector, however, there is a preference for protecting them. From the undersecretary’s words, it did not seem to me that there was any intention to find out what happened, let alone to put things right.”
The case is well known: a group of cybercriminals calling themselves ‘IamNotAVillain’ managed to get Revolut to hand over the data of hundreds of users by using a certified email address belonging to the Prefecture of Reggio Calabria and posing as an investigating authority requesting the data for a European investigation. According to the hackers, the attack was the result of months of covert work, which allegedly secured them 147 gigabytes of data, including internal documents and agents’ chat logs. “And that’s just the tip of the iceberg,” emphasises Pastorella.
“It is well known that there is a black market for access to institutional certified email accounts (PEC). One is therefore led to wonder why it is so easy to gain access to our most critical infrastructure, but also whether these systems are being properly monitored.” Among the more than 3,000 malicious campaigns recorded in 2025 by CERT-AgID – the body responsible for supporting the public administration in cybersecurity – there has been a significant increase in the use of certified email (PEC) as a vector for attack, almost doubling compared with the previous year. “That is why,” continues Pastorella, “I would have expected a more robust response from the Ministry of the Interior – and, above all, an acceptance of responsibility – because the Under-Secretary represents the very ministry that these malicious actors managed to infiltrate. But I would also have expected a commitment to ensure that the third-party provider of the PEC service is placed under scrutiny.” However, none of this has materialised, despite the figures highlighting a certain urgency to take action. “According to the European Union Agency for Cybersecurity, Italy ranks second in Europe for the number of incidents in the public administration, with a share of 26.3 per cent, just behind France at 27 per cent,” notes the MP. “I would never want the Reggio Calabria Prefecture to be found guilty of simply having set a password that was too simple and perhaps having removed the two-factor authentication system. That would be truly sad.”
On this matter, Revolut acted “in perfect good faith”, notes the MP. “Having received a certified email from the prefecture, what was it supposed to do? After all, the EU e-Evidence Regulation has been in force since August, under which, for example, an Italian authority can request information from a company in another country without going through Europol or other filters. So, Revolut responded very quickly. Perhaps even too quickly.” Faced with such a scenario, one wonders how Italy is managing its cybersecurity efforts. Defence Minister Guido Crosetto has repeatedly emphasised its absolute importance – does the same apply to the rest of the government? “I don’t think it has committed itself all that much to the issue. There is a general underestimation of the issue, because people continue to think it’s a matter for technicians. But in reality, there’s nothing more political about it, and this applies not only to the attacks themselves, but also to the consequences.” The Action Programme is still being drawn up, but Pastorella gives us a preview of how the party intends to tackle the issue: “We need to enhance digital sovereignty and European independence, including by building data centres and critical infrastructure on our own territory. But we must also work very hard on the adoption of cybersecurity solutions and artificial intelligence within our manufacturing sector.”
