Hackers Who Hit Revolut Demand $3M in Ransom as Part of an Unusual Breach

LONDON — Hackers compromised an Italian government email system and allegedly posed as law enforcement officials to obtain sensitive information on hundreds of Revolut customers over several months, and are now demanding nearly $3 million from the online financial company to keep the data from being sold.

The hacking group, calling itself “iamnotavillain,” is threatening to sell confidential information involving at least 680 Revolut customer accounts unless the company pays 6,000 units of the cryptocurrency Monero within 24 hours, the Finanial Times reported.

The cryptocurrency was worth about $2.9 million as of early Thursday.

Revolut told the Financial Times it had not received a ransom demand directly from the group. “Revolut has not received any direct contact or demand from the individuals or group making these claims,” the company said.

Law Enforcement Impersonated

According to the FT, the breach did not result from hackers penetrating Revolut’s own systems. Instead, the attackers compromised an Italian government email system and allegedly used it to impersonate law enforcement authorities seeking information about specific Revolut customers.

The requests were made over several months and were aimed at obtaining information on wealthy cryptocurrency holders, often referred to as “crypto whales,” at Revolut, according to earlier reporting by the Financial Times.

The compromised information included sensitive documents collected as part of Revolut’s know-your-customer, or KYC, identity verification procedures.

Hackers Send Video

Soon after publicly issuing its ransom demand, the hacking group sent the Financial Times a video that purportedly showed an unidentified person browsing through a cache of Revolut documents. The material appeared to include customer driver’s licenses, passports and identity photographs used for KYC verification.

The public ransom demand itself is unusual, according to the FT. Cybercriminals typically make extortion demands privately and disclose details of an attack publicly or on the dark web only after a victim refuses to pay or negotiate.

The hackers warned that if Revolut did not pay, “all the data will be sold, and the blood will be on your hands,” according to the Financial Times.

Revolut has said its systems and customer funds were not affected by the breach.

The company also said it has notified law enforcement authorities and regulators about the incident.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.