No hacked servers, no cracked encryption. For months, a genuine certified email address sent requests for confidential data from hundreds of bank customers. The lesson isn't about certified email technology, but how organizations choose to trust it.
Speed has become one of the key indicators of digital transformation. Organizations are required to introduce new tools, automate processes , and develop operational solutions in ever-shorter timeframes. Acceleration is now considered a necessary requirement to remain competitive. Yet, just as they strive to become faster, many companies risk achieving the opposite effect. Let's find out why.
What happened
The news circulated quickly and was confirmed by Revolut: an unauthorized individual had sent requests for information from authentic certified email addresses of a government agency and for this reason the company considered them to be authentic requests from an authority.
According to reconstructions, the mailbox was a certified email address of the Reggio Calabria prefecture, which ended up under the control of criminals via an infostealer (malware that steals login credentials), and the requests were submitted in the name of the Postal Police.
Sensitive data of approximately 680 account holders , including identity documents, accounts, and bitcoin transactions, was handed over , and the fraud is believed to have continued for approximately five months before being discovered. The bank states that its systems and customer funds were not affected.
The Postal Police and the UK Data Protection Authority are investigating for unauthorised access and computer fraud.
No technical checks failed
This is precisely what makes the case instructive. The domain and the certification guaranteed by the provider passed all the checks. PEC did exactly what it was designed to do: guarantee that the message originated from that inbox. But PEC does not, and cannot, guarantee the identity of the sender or whether the content is legitimate. The authenticity of the channel is a technological problem, and PEC solves it. The legitimacy of the request is a process problem, and no channel can resolve it alone.
The signals were there, what was missing was a process to read them
In hindsight, there was no shortage of clues. The requests were signed by the Postal Police but originated from a prefecture's certified email address, whereas the Postal Police has its own certified email address.
Furthermore, the judicial authority decree that typically accompanies requests of this type appears to be missing. Each of these elements corresponds to a verifiable rule: who is the competent party, which channel they usually use to write, which attachments are required. Added to this is a data point observable over time: a sequence of requests spread over months.
There's a second detail. The requests continued until the bank decided to investigate further and contacted the Italian institution directly, which denied being the source.
The definitive control, therefore, existed: a human verification through an independent channel. The problem is that it arrived months later, on initiative and not by design.
Learn how to build, model, and govern business processes
From identity verification to consistency verification
Identifying who sent a message is no longer enough. We need to ask ourselves: is it normal for this person to ask us this question, in this way, at this time?
Responding requires cascading checks, and order matters:
- Deterministic rules, i.e. the process design: competence, expected channel, mandatory documentation.
- Statistics and anomaly detection on frequencies and volumes.
- Semantic similarity to communications already received.
- Content analysis with linguistic models, compared with the sender's history.
In effect, it's a process that uses AI agents that extend control beyond the reach of rules and can read the content and compare it with the history of the relationship (on volumes that no protocol office could ever manually examine in such a short time). This infrastructure must be Private AI, given the confidentiality of the information processed.
Where the person remains
In this model, the agent doesn't decide to release data. It extracts, classifies, assigns a risk level , and passes the file to a human along with the collected evidence. This allows for more sensitive requests, such as disclosing personal data to an authority, to be verified by the Human in the Loop before execution. And every step is tracked.
This is the concrete meaning of Human in the Loop: establishing by design who makes decisions, on what elements, and with what traceability. It's not about adding a human check "for security." This is what actually happened in the Revolut case, but five months too late.
The Jamio Solution
The Jamio solution for managing incoming communications (PEC/PEO) , already adopted by numerous organizations to structurally manage the acquisition and processing of communications, is enriched with a new player: an agent system natively integrated into the platform.
The system, based on a private architecture designed to preserve the confidentiality of information, analyses the received communications and their contents, automatically extracting the relevant information.
The information identified is integrated with the data and context already present in Jamio, allowing the system to interpret the message not as an isolated element, but within the context of the processes, information and relationships already managed by the platform.
Based on the elements thus collected, the agentic system proposes a classification of the message and provides the evaluator with useful information to support the evaluation and subsequent decisions.
In this case, Jamio could have detected that the behavior of a seemingly trustworthy sender was inconsistent with their historical profile. And that's exactly the signal that, in this case, no one picked up on for months.
Organizations will continue to invest in perimeter protection, and rightly so. But the decision to trust is a process, and like any process, it must be designed, governed, and auditable. With agents reading and people deciding.
Organizations will continue to invest in perimeter protection, and rightly so. But the Revolut case shows that the critical point lies elsewhere: the moment when a decision is made to follow up on a request. That moment must be designed, governed, and made verifiable. With agents who read and propose, and people who decide. Because trust isn't certified. It's governed.