Hackers Demand $3mn From Revolut After Data Breach

Criminal group threatens to sell confidential customer records unless Europe’s biggest fintech pays a ransom in Monero within 24 hours.

2 mins read
Revolut

Hackers claiming responsibility for a data breach at Revolut have threatened to sell confidential records belonging to hundreds of customers to other criminal groups unless the British online bank pays a ransom of $3mn within 24 hours.

The group, which calls itself iamnotavillain, published the ultimatum online on Wednesday afternoon alongside a digital countdown clock. The public demand is unusual because hackers typically make ransom requests privately and go public only if a target refuses to pay or engage, usually by publishing details of the hack on a dark-web leak site.

The message told Revolut to pay “6,000 XMR / $3,000,000 . . . otherwise all the data will be sold, and the blood will be on your hands”. XMR is the cryptocurrency Monero, which is popular with hackers because its transactions are difficult to trace. The group told the Financial Times that it was using the website to make its demands for the first time and that there had not yet been any negotiations with Revolut.

The Financial Times contacted the hackers via Telegram after they first set up the website late on Monday, when it displayed redacted screenshots of some of the information allegedly obtained from the bank. Shortly after posting the ransom demand, the hackers sent the Financial Times a 60-second screen-capture video showing an unseen user moving through a cache of purported Revolut documents.

The documents shown in the video appeared to include Revolut customers’ driving licences, passports, identity pictures used during the “know your customer” verification process and transaction histories. The data breach is understood to have affected at least 680 customer accounts, with several affected customers expressing concern that their personal data had been compromised.

According to the Financial Times, the hackers obtained the files by compromising an Italian government email system. They allegedly used the system to pose as law enforcement and demand information on specific Revolut client accounts over several months. The group said it selected its targets by using blockchain analysis to identify Revolut accounts with significant crypto holdings.

The reported breach comes as Revolut has grown into Europe’s biggest fintech since its launch in 2015. The company operates as a bank in more than 30 countries and serves 80mn customers. It was recently valued at $115bn in a secondary share sale, placing the alleged compromise against the backdrop of a financial technology company with a large international customer base.

The nature of the information allegedly accessed has heightened concerns among affected customers, particularly because the material shown by the hackers appeared to contain both identity documents and transaction histories. The group’s threat to sell the records to other criminal groups adds another dimension to the reported breach.

Revolut declined to comment on the purported hackers’ ransom demand. The bank previously said it was providing affected customers with “immediate support” and “working closely with relevant law enforcement and regulatory authorities”.

With the hackers demanding $3mn within 24 hours and threatening to sell the data if the ransom is not paid, the reported breach has moved into a public confrontation between the criminal group and one of Europe’s largest fintech companies.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog