Back Govinfosecurity Crypto Industry Figures Blackmailed by Revolut's Hacker
The hacker who stole data from digital financial platform Revolut obtained the personally identifiable information of multiple high-risk individuals, prompting warnings for these customers' personal safety.
See Also: OnDemand | 2024 Phishing Insights: What 11.9 Million User Behaviors Reveal Your Risk
After directly notifying affected customers on Saturday, Revolut publicly confirmed that it fell victim to a social engineering attack involving requests for customer data issued using a legitimate - but subverted - government email account.
"Fraudsters exploited a legitimate government email domain that passed Revolut's technical authentication checks - SPF/DKIM/DMARC - to send deceptive information requests," said threat intelligence firm Kela in a Tuesday report.
"Mistaking these demands for authentic official orders, Revolut's compliance and legal team manually released sensitive files for a limited group of users," Kela said.
Founded in 2015, London-based Revolut operates banks in 30 countries, and offers digital banking, multi-currency accounts, cryptocurrency exchange, insurance and other financial services through its mobile app. The company this month said it has over 80 million customers worldwide, and it's reportedly eying an initial public offering year that could value the company at up to $200 billion.
Revolut said the threat actor did not steal customer funds or break into Revolut systems, and obtained sensitive data for a "very limited" number of customers. Types of data that were exposed included a customer's name, information, bank account and cryptocurrency wallet details, lists of transactions, and copies of documents used to prove identity, as part of know-your-customer or KYC checks, including driver's licenses and passports, as well as selfies, it said.
The Financial Times reported that Revolut's victim count numbers 680 customers. Screenshots posted by the threat actor who claimed credit for the attack, "IAmNotAVillain," also show a folder comprising 326 megabytes of data and 688 files.
The data-stealing campaign ran for six months and started with their gaining access to a system used by Italian federal agents, by infecting it with a remote-access Trojan, IAmNotAVillain told Alon Gal, CTO of threat intelligence firm Hudson Rock.
The threat actor claimed they used this access "to socially engineer Revolut" into giving them sensitive information, including for customers outside of Italy, Gal said in a Monday post to .
Online crypto casino and sports betting platform Duel.com employee "Korra" said in a post to social platform X they've been in with the hacker, who claimed they infected an Italian government system with an info stealer. "After gaining access to an employee's email, they would log in, add their own recovery email, start to log everything and silently listen in," they said.
Over a five-month period, the threat actor experimented with various social engineering approaches, ultimately tricking Revolut's Lithuania-based bank by sending them a European Investigation Order using the subverted Italian government agency email account, Korra said.
Crypto Figures Targeted
The exposure of sensitive personal information pertaining to cryptocurrency owners has personal safety repercussions. "Lives are now at risk. I'm personal friends with one of the victims, and he'll probably have to move houses due to the continued (credible) kidnap threats," Korra said.
While 680 victims might not sound like a large number - some American states have a 1,000-victim threshold before a breached business needs to notify a state attorney general or regulator - attackers' focus appeared to be high-net-worth individuals, said cryptocurrency investigator ZachXBT.
French businessman Mark Karpelès, the former CEO of bitcoin exchange Mt. Gox, said he was one of the customers who received Revolut's breach notification, informing him that his personal information was stolen. He initially asked Revolut, using an X post, if the alert was a scam.
Other cryptocurrency figures also reported falling victim. "Woke up to all my data leaked by Revolut. Sharp reminder that KYC hasn't produced meaningful upside and has put many in harm's way," cryptocurrency entrepreneur Marc Zeller posted to X. He said the timing of the notification was notable, since Revolut had threatened to close his account within 20 days unless he provided additional, personal data.
The threat actor was attempting to directly extort multiple customers. Felix Romer, founder of the Thailand-based online crypto gambling platform Gamdom, posted that while Revolut first disclosed the breach to customers Saturday, "already 2 months ago me and others started to get blackmailed with the compromised data." His post to X included a Discord chat screenshot showing an extortion attempt against him, dated July 26.
IAmNotAVillain said it's the real threat actor, warning victims to not negotiate with anyone else. "An impersonator and scammer who used to work with us took a small sample we handed him and is now claiming the breach as his. That cut is not the full set," it said.
The threat actor told Europe-based news site International Cyber Digest that most of the stolen data comes from Revolut customers in France and Switzerland, but claims Revolut also handed over data from residents of nearly every member of the European Union as well as Norway, Turkey, the United Kingdom and the Bahamas.
On Monday, IAmNotAVillain created a clearnet data-leak site to advertise the stolen data, which it said included customers' "crypto withdrawals," "crypto deposits" and "fiat transactions (bank sends and receives)." The threat actor also leaked a sample of the supposedly stolen data, including partially redacted ID documents.
"Your KYC documents stay the same. It is the file they keep on you: name, mail, phone, address, account identifiers, ID scans. That is enough to impersonate support, reset access, or try the same profile on another service. A bank is supposed to keep that closed," the data-leak site reads.
The data-leak site, iamnotavillain.xyz , was offline by Tuesday, after having first been registered with domain name registrar GoDaddy on Monday.
Fraud Management & Cybercrime
Executive Editor, DataBreachToday & Europe, ISMG
Schwartz is an award-winning journalist with two decades of experience in magazines, newspapers and electronic media. He has covered the information security and privacy sector throughout his career. Before joining Information Security Media Group in 2014, where he now serves as the executive editor, DataBreachToday and for European news coverage, Schwartz was the information security beat reporter for InformationWeek and a frequent contributor to DarkReading, among other publications. He lives in Scotland.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
