Revolut disclosed on September 12 that unauthorized client data was exposed following fake information requests from an email address mimicking a legitimate government domain. This breach includes sensitive personal data of customers, particularly tied to Bitcoin transactions, which could encompass verification selfies, account statements, and transaction histories.
The attackers, who identified themselves as Revolut Smilik, have demanded a ransom of 10,000 Bitcoin, equivalent to over $782 million, threatening to publish more customer information if their demands are not met. So far, they have leaked personal data of tennis player Alexander Shevchenko and Gamdom CEO Felix Römer.
Importantly, the data breach did not stem from direct access to Revolut’s data centers or internal systems. Instead, the attackers exploited the protocols in place for handling mandated information requests from authorities. They crafted an email using a legitimate government agency's domain to forge a request for customer details. This deception allowed them to bypass compliance checks, leading Revolut to mistakenly fulfill the request before it was discovered to be fraudulent.
In response to the breach, Revolut blocked the fake email address and notified the government agency involved. They have reported the incident to law enforcement and data protection authorities. At the time of reporting, Revolut indicated that only a small number of customers were impacted and reached out to those affected with precautions against further threats.
In communications to customers, Revolut explained the series of events, noting that they received a request fraudulently posed as a legitimate inquiry from a government agency, which was authenticated with genuine credentials. Once the issue was identified, they contacted the relevant government representatives to alert them about the unauthorized account and quickly implemented measures to secure their systems.
ZachXBT, a cryptocurrency investigator, shared additional details on Telegram regarding the leaked data, revealing more specifics such as IBANs, withdrawal history, jobs, and Bitcoin transaction histories. He characterized the incident as relatively limited but pointedly targeting affluent individuals.
This incident underscores the risks associated with fraudulent requests that appear to come from credible government domains, signaling the need for banks and fintech companies to bolster verification processes and improve methods for identifying abnormal activities before disclosing sensitive customer information.
