<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Revolut Hit with $3M Ransom Demand After 5-Month Data Breach

An attacker claiming 680 Revolut accounts has cut an opening demand of 10,000 Bitcoin and threatened to sell the files to other criminals.
Content Team

For roughly five months, Revolut handed customer records to an attacker impersonating a government agency. The fraudulent legal requests went to Revolut Bank UAB, the Lithuanian subsidiary, from a compromised Italian Ministry of the Interior mailbox, which is why they cleared authentication and were processed as routine.

Hudson Rock traced the access to infostealer malware on a ministry employee's machine, and assesses the attacker probably bought those credentials rather than deploying the malware. The attacker, who uses the handle IAmNotAVillain, claims 680 accounts held by cryptocurrency whales, with files containing passports, verification selfies, and full Bitcoin transaction histories. Revolut has still not confirmed a victim count.

The extortion came next. An initial demand of 10,000 Bitcoin, around $780 million, was cut to 6,000 Monero, roughly $3 million, with a 24-hour deadline to sell the files to other criminal groups. Revolut says it has had no direct contact from anyone making the claims, and notified affected customers on September 12.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo