Hackers Exploit Italian Government Email to Target Revolut Users in Data Breach
In a significant data breach, hackers hijacked a legitimate email address from Italy's Ministry of Interior to impersonate law enforcement and extract personal information from Revolut, a London-based fintech company. The breach, which occurred around September 11-12, has left approximately 700 customers vulnerable as their identity documents, passports, selfies, IBANs, and Bitcoin transaction histories were exposed.
The attackers, who identified themselves as "I Am Not A Villain" on Telegram, sent fraudulent emergency data requests to Revolut, exploiting the trust that companies place in official-looking communications. Revolut complied with the requests without realizing the legitimacy of the emails was compromised, leading to the unauthorized release of sensitive customer data.
Following the breach, the hackers initiated an extortion campaign, demanding a ransom of 10,000 Bitcoin from the affected users. Investigations are currently underway in Italy and the UK, focusing on the methods used to compromise the email account and the adequacy of Revolut's data handling practices.
Revolut has confirmed that its internal systems were not breached and that customer funds remain secure. The company promptly blocked the compromised email account and notified the relevant authorities and affected users.
FAQ
What happened in the recent data breach involving Revolut?
Hackers exploited a legitimate email address from Italy's Ministry of Interior to impersonate law enforcement and extract personal information from Revolut users, affecting approximately 700 customers.
What kind of personal information was exposed in the breach?
The exposed information includes identity documents, passports, selfies, IBANs, and Bitcoin transaction histories of the affected users.
How did the hackers manage to extract information from Revolut?
The attackers sent fraudulent emergency data requests to Revolut, exploiting the trust in official-looking communications, which led Revolut to comply without realizing the emails were compromised.
What actions have been taken by Revolut following the breach?
Revolut blocked the compromised email account, notified the relevant authorities, and informed the affected users while confirming that their internal systems were not breached and customer funds remain secure.
What are the hackers demanding from the affected users?
The hackers have initiated an extortion campaign, demanding a ransom of 10,000 Bitcoin from the affected users.
Comments
Comments are moderated before publish.
No comments yet — be the first.