Revolut Hacker Launches Extortion Site Demanding $3M After 680 Customer Data Breach | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Key Takeaways

  • A group claiming responsibility for the Revolut breach has demanded 6,000 Monero, worth roughly $3 million, and threatened to sell stolen customer records.

  • Around 680 customers were affected after fraudulent data requests were sent using an email account on a legitimate Italian government domain.

  • Revolut says its own systems and customer funds were not compromised and that it has received no direct ransom demand from the alleged attackers.

Hackers claiming responsibility for Revolut’s recent customer data breach have launched a public extortion site demanding $3 million in Monero, escalating an incident that exposed sensitive information belonging to hundreds of customers.

The group, calling itself “iamnotavillain,” posted a demand for 6,000 XMR alongside a 24-hour countdown, threatening to sell the stolen records to other criminal groups if Revolut refused to pay.

Revolut, however, told Reuters that it had received no direct communication or ransom demand from the people claiming responsibility and had not entered negotiations.

680 Customers Exposed Without Revolut Being Hacked

The breach did not begin with attackers breaking into Revolut’s core systems.

Instead, an unauthorized party used an email account on a legitimate government agency domain to submit fraudulent requests for customer information. Revolut complied with some of those requests before discovering the deception and blocking the address.

Around 680 customers across several European countries were affected, according to people familiar with the incident. Potentially exposed records included names, home addresses, phone numbers, identity documents, verification selfies, IBANs and transaction histories —including information about Bitcoin activity.

The attackers told the Financial Times they had compromised an Italian government email system and used blockchain analysis to identify Revolut customers believed to hold significant amounts of cryptocurrency. Revolut has not independently confirmed those claims.

Former Mt. Gox CEO Mark Karpelès was among those affected and has publicly raised concerns about the physical-security implications of having home addresses and crypto-related information exposed.

Italian Prosecutors Open Investigation

The incident has now drawn law-enforcement attention in Italy.

Prosecutors in Reggio Calabria have opened an investigation after the fraudulent requests were linked to an institutional email account belonging to the local prefecture. Authorities are examining whether the government system itself was breached or whether the account was cloned. Italy’s National Anti-Mafia and Anti-Terrorism Directorate is also involved.

Revolut maintains that customer funds and its internal systems remain unaffected and says it has notified law enforcement, regulators and affected customers.

The breach nevertheless highlights a different security problem: attackers did not need to penetrate an 80-million-customer fintech’s infrastructure. They allegedly exploited the trust attached to a government email account instead.

Top Trending Crypto Articles

The post Revolut Hacker Launches Extortion Site Demanding $3M After 680 Customer Data Breach appeared first on ccn.com.



Click Here For The Original Source.

——————————————————–

..........

.

.