Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Revolut, a British fintech company, suffered a significant data breach after responding to fraudulent government requests over five months. Hackers, posing as official agencies, gained access to the company's systems, leading to the compromise of personal and financial data for approximately 680 high-profile customers, including cryptocurrency investors. The attackers are now demanding $3 million for the stolen data, and an Italian police investigation is underway.
Revolut, a British fintech company, has been targeted in a data breach following a prolonged campaign of fraudulent government requests. Over five months, hackers impersonated official government agencies and successfully obtained access to Revolut's systems. The attackers initially compromised a government employee’s accounts via an infostealer infection, utilizing the compromised email address to send fraudulent requests to Revolut Bank UAB, the Lithuania-based subsidiary of the British firm.
Revolut Bank UAB reportedly responded to these requests without questioning their legitimacy, allowing the attackers to steadily accumulate data. The Duel investigations team has established contact with the threat actor, who is demanding $3 million for the stolen customer information.
According to the hacker, a sample of the exfiltrated information was in the hands of a former associate, and the campaign involved the theft of over 147GB of data from a law enforcement agency in Italy. The Italian police have launched an investigation into the matter.
SecurityWeek understands that the personal and financial information of approximately 680 Revolut customers, including many cryptocurrency investors, was compromised. The compromised email address on pec.interno.it appears to belong to an employee within the Italian Ministry of the Interior. The cybersecurity firm notes that it is aware of more than 300 compromised credentials associated with pec.interno.it, and believes the attacker likely purchased or utilized existing Infostealer logs containing these credentials to obfuscate their initial access method.