Revolut Hit with $3M Ransom Demand After 5-Month Data Breach
Want more insights like this?
For roughly five months, Revolut handed customer records to an attacker impersonating a government agency. The fraudulent legal requests went to Revolut Bank UAB, the Lithuanian subsidiary, from a compromised Italian Ministry of the Interior mailbox, which is why they cleared authentication and were processed as routine.
Hudson Rock traced the access to infostealer malware on a ministry employee's machine, and assesses the attacker probably bought those credentials rather than deploying the malware. The attacker, who uses the handle IAmNotAVillain, claims 680 accounts held by cryptocurrency whales, with files containing passports, verification selfies, and full Bitcoin transaction histories. Revolut has still not confirmed a victim count.
The extortion came next. An initial demand of 10,000 Bitcoin, around $780 million, was cut to 6,000 Monero, roughly $3 million, with a 24-hour deadline to sell the files to other criminal groups. Revolut says it has had no direct contact from anyone making the claims, and notified affected customers on September 12.
Source: SecurityWeek