Revolut leaked data of 680 customers after fake government requests
Revolut has disclosed sensitive data from 680 customers after cybercriminals submitted false information requests through a legitimate government email account. According to the Financial Times, the data includes passport details, bank account numbers, home addresses, identity verification photos and Bitcoin activity. The attackers are threatening to make the data public unless a ransom is paid. The British privacy regulator, the ICO, has launched an investigation.
In brief:
- Criminals used a hacked Italian government account to trick Revolut into releasing customer data.
- The leaked information includes passport details, bank details, addresses and Bitcoin activity of 680 customers.
- A second party also claims to be behind the data leak; the ICO has launched an investigation.
Fake government requests led to data leak
Criminals gained access to an official Italian government email account and used it to submit data requests to Revolut that appeared to be legitimate legal obligations. Revolut then released data on 680 customers, including sensitive personal and financial information.
Those affected reportedly include Mark Karpelès, the former CEO of the now-bankrupt Bitcoin platform Mt. Gox. The attackers are now demanding a ransom and threatening to publish the data if it is not paid. Revolut says it has blocked the email account involved and informed both regulators and affected customers.
Hacker claims to have also hacked Italian police services
International Cyber Digest reports that it has been in contact with the person claiming responsibility for the attack. According to this person, the operation targeting Revolut lasted six months and the attackers used hacked Italian police systems to send the data requests.
The attacker additionally claims to possess 147 GB of data from the Italian side, including internal documents, calendars and personal material. The reliability of these claims has not yet been independently verified.
Second party also claims responsibility
International Cyber Digest also reports that it has been in contact with a second party that says it is behind the Revolut data leak. This group calls itself “Revolut Smilik” and says it has launched its own website.
Further evidence from this second party is still awaited. Whether it is the same attack or a separate action is currently unclear. The ICO has confirmed that it has opened an investigation into the incident at Revolut.
Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.
Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.