Crypto Industry Figures Blackmailed by Revolut’s Hacker | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Cryptocurrency Fraud
,
Cybercrime
,
Fraud Management & Cybercrime

Payments Platform Socially Engineered With Hacked Government Agency Email Account

Image: Shutterstock/ISMG

The hacker who stole data from digital financial platform Revolut obtained the personally identifiable information of multiple high-risk individuals, prompting warnings for these customers’ personal safety.

See Also: OnDemand | 2024 Phishing Insights: What 11.9 Million User Behaviors Reveal About Your Risk

After directly notifying affected customers on Saturday, Revolut publicly confirmed that it fell victim to a social engineering attack involving requests for customer data issued using a legitimate – but subverted – government email account.

“Fraudsters exploited a legitimate government email domain that passed Revolut’s technical authentication checks – SPF/DKIM/DMARC – to send deceptive information requests,” said threat intelligence firm Kela in a Tuesday report.

“Mistaking these demands for authentic official orders, Revolut’s compliance and legal team manually released sensitive files for a limited group of users,” Kela said.

Founded in 2015, London-based Revolut operates banks in 30 countries, and offers digital banking, multi-currency accounts, cryptocurrency exchange, insurance and other financial services through its mobile app. The company this month said it has over 80 million customers worldwide, and it’s reportedly eying an initial public offering next year that could value the company at up to $200 billion.

Revolut said the threat actor did not steal customer funds or break into Revolut systems, and obtained sensitive data for a “very limited” number of customers. Types of data that were exposed included a customer’s name, contact information, bank account and cryptocurrency wallet details, lists of transactions, and copies of documents used to prove identity, as part of know-your-customer or KYC checks, including driver’s licenses and passports, as well as selfies, it said.

The Financial Times reported that Revolut’s victim count numbers about 680 customers. Screenshots posted by the threat actor who claimed credit for the attack, “IAmNotAVillain,” also show a folder comprising 326 megabytes of data and 688 files.

The data-stealing campaign ran for about six months and started with their gaining access to a system used by Italian federal agents, by infecting it with a remote-access Trojan, IAmNotAVillain told Alon Gal, CTO of threat intelligence firm Hudson Rock.

The threat actor claimed they used this access “to socially engineer Revolut” into giving them sensitive information, including for customers outside of Italy, Gal said in a Monday post to LinkedIn.

Online crypto casino and sports betting platform Duel.com employee “Korra” said in a post to social platform X they’ve been in contact with the hacker, who claimed they infected an Italian government system with an info stealer. “After gaining access to an employee’s email, they would log in, add their own recovery email, start to log everything and silently listen in,” they said.

Over a five-month period, the threat actor experimented with various social engineering approaches, ultimately tricking Revolut’s Lithuania-based bank by sending them a European Investigation Order using the subverted Italian government agency email account, Korra said.

Crypto Figures Targeted

The exposure of sensitive personal information pertaining to cryptocurrency owners has personal safety repercussions. “Lives are now at risk. I’m personal friends with one of the victims, and he’ll probably have to move houses due to the continued (credible) kidnap threats,” Korra said.

While 680 victims might not sound like a large number – some American states have a 1,000-victim threshold before a breached business needs to notify a state attorney general or regulator – attackers’ focus appeared to be high-net-worth individuals, said cryptocurrency investigator ZachXBT.

French businessman Mark Karpelès, the former CEO of bitcoin exchange Mt. Gox, said he was one of the customers who received Revolut’s breach notification, informing him that his personal information was stolen. He initially asked Revolut, using an X post, if the alert was a scam.

Other cryptocurrency figures also reported falling victim. “Woke up to all my data leaked by Revolut. Sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way,” cryptocurrency entrepreneur Marc Zeller posted to X. He said the timing of the notification was notable, since Revolut had threatened to close his account within 20 days unless he provided additional, personal data.

The threat actor was attempting to directly extort multiple customers. Felix Romer, founder of the Thailand-based online crypto gambling platform Gamdom, posted that while Revolut first disclosed the breach to customers Saturday, “already 2 months ago me and others started to get blackmailed with the compromised data.” His post to X included a Discord chat screenshot showing an extortion attempt against him, dated July 26.

Two threat actors have claimed credit for the breach: A Telegram channel run by IAmNotAVillain, as well as another Telegram channel operated by “Revolut Smilik.” Both Telegram channels with the cloud-based instant messaging and social media operator said they violated its terms of service.

IAmNotAVillain said it’s the real threat actor, warning victims to not negotiate with anyone else. “An impersonator and scammer who used to work with us took a small sample we handed him and is now claiming the breach as his. That cut is not the full set,” it said.

The threat actor told Europe-based news site International Cyber Digest that most of the stolen data comes from Revolut customers in France and Switzerland, but claims Revolut also handed over data from residents of nearly every member of the European Union as well as Norway, Turkey, the United Kingdom and the Bahamas.

On Monday, IAmNotAVillain created a clearnet data-leak site to advertise the stolen data, which it said included customers’ “crypto withdrawals,” “crypto deposits” and “fiat transactions (bank sends and receives).” The threat actor also leaked a sample of the supposedly stolen data, including partially redacted ID documents.

“Your KYC documents stay the same. It is the file they keep on you: name, mail, phone, address, account identifiers, ID scans. That is enough to impersonate support, reset access, or try the same profile on another service. A bank is supposed to keep that closed,” the data-leak site reads.

The data-leak site, iamnotavillain.xyz, was offline by Tuesday, after having first been registered with domain name registrar GoDaddy on Monday.





Click Here For The Original Source.

——————————————————–

..........

.

.