Revolut, a leading British fintech company, is under pressure as hackers demand a $3 million ransom following a severe data breach. For five months, hackers accessed sensitive data by submitting fraudulent government requests, exploiting the company’s obligation to comply with law enforcement demands.
Details of the Data Breach
Last week, Revolut alerted users that personal details, including passports, emails, phone numbers, and financial data, were compromised. The breach occurred as hackers impersonated a government agency to extract this information. Despite inquiries, Revolut has not disclosed which agency was impersonated or how many individuals were affected.
On Wednesday, the hacker, identified as ‘IAmNotAVillain’, publicly demanded $3 million in ransom, threatening to sell the acquired data. However, Revolut has not received any direct communication from the hacker, according to their spokesperson.
Extent of the Compromise
The breach impacted approximately 680 Revolut customers, many of whom are believed to be significant cryptocurrency investors. The operation involved compromising a government employee’s email through an infostealer infection, enabling the hacker to send fake requests to Revolut’s Lithuanian subsidiary, Revolut Bank UAB.
Reports indicate that the hackers also obtained over 147GB of data from an Italian law enforcement agency. The Italian police are currently investigating the breach, which involved a compromised email account within the Ministry of the Interior.
Analysis and Future Outlook
Cybersecurity firm Hudson Rock suggests that the hackers likely acquired existing credentials rather than actively infecting specific employees. This breach highlights vulnerabilities in data handling and the challenges fintech companies face in distinguishing legitimate from fraudulent requests.
As investigations continue, the incident underscores the critical need for enhanced security measures and vigilance in responding to governmental data requests. The outcome of this situation may prompt regulatory changes and increased scrutiny on data protection practices across the fintech industry.
