They made a grave mistake for not conducting due diligence in communication before releasing such sensitive information.
At first, upon receiving such request, they ought to have contacted the requesting organisation or the government directly from the usual method or pattern they normally communicate. This would have justified the request and prepared them for the next line of action so the don't make such a mistake but unfortunately they were quick to release customers information and failed to verify the source of the request. Maybe it could be an inexperienced worker who was on duty that day or he might have been high on something.
This is a clear case of unprofessional conduct from the staff who released the data without a proper verification because before such sensitive information should have been released, they ought to have verified it properly from their end as it would definitely put lives in danger of such information leaks to the public. Now this is the situation of it and how do they protect customers whose information is already in the hands of criminals they know not.
The attack was well planned and, I must say, very subtle. They first breached the security systems of Italian government officies, gaining access to official emails linked to the Italian Finance Police (yes, in Italy we have such a daft thing) and then to government emails from the ministry. At that point, Revolut thought it was an usual data cross reference caused by an Italian "tax tool index" called the "redditometro" or measure of the income (another daft thing).
They monitored the situation for a full six months before taking action.
In my view, we are underestimating the firepower of AI; we think these attacks are random or the result of bruteforce attacks, but in reality, AI now solves the logical structures associated with passwords.
No crime that do not occur unplanned. These attack was a well planned out event and it is disappointing that even after receiving report about the lapses in the path of revolut, they ignored putting data of their customers at risk just because of their ignorance.
If the hackers could have monitored the system for six months, it means revolut was nonchalant and does not really care about the safety of their customers as all they want is just do business and the rest is not their concern and that was what I believe made the hackers took time to observe the situation before they struck.