ZeroHour
SecurityWeekpublished ()ingested Ionut Arghire
Part of a story covered by 2 sources: “Revolut Data Leak Traced to Compromised Italian Government PEC Mailbox as Threat Actor Demands $3M Ransom” — merged summary and timeline →

Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

highData breach exploited in the wildimportance 72
AI summary · glm-5.3-flash

A threat actor demanding $3 million from Revolut says fake government legal requests yielded data of about 680 customers, mostly cryptocurrency whales.

Hackers used an infostealer-compromised government employee's email account to send fraudulent legal requests to Revolut Bank UAB in Lithuania for roughly five months, obtaining personal and financial data. Threat actor 'IAmNotAVillain' publicly demanded $3 million, though Revolut says it received no direct demand; the compromised data of approximately 680 high-profile customers, reportedly crypto whales, includes passports, phone numbers, and financial information. The actor also claims the theft of over 147GB of data from Italy's Interior Ministry (pec.interno.it), which is under police investigation. Hudson Rock says it knows of more than 300 compromised credentials tied to pec.interno.it, suggesting existing infostealer logs were used rather than fresh infections.

  • Threat actor 'IAmNotAVillain' publicly demanded $3 million from Revolut
  • About 680 customers, reportedly crypto whales, had data exposed
  • Campaign used fake government legal requests for roughly five months
  • Access relied on an infostealer-compromised government email account
  • Hackers also claim 147GB theft from Italian law enforcement
Full article467 words · extracted from securityweek.com · click to collapse

Hackers are demanding a $3 million ransom from the British fintech giant Revolut after siphoning data from it through fake government requests for five months.

Last week, the company notified potentially affected users that their personal information, passports, email addresses, phone numbers, and financial information were compromised in the data breach.

To obtain the information, the hackers posed as an official government agency. Because Revolut is required to respond to legal requests from law enforcement, it complied.

The company refrained from sharing the name of the impersonated government agency or the number of impacted individuals when contacted by SecurityWeek.

On Wednesday, a threat actor using the moniker ‘IAmNotAVillain’ publicly demanded $3 million from Revolut, threatening to sell the customer information allegedly obtained from the company.

However, it appears that the alleged hacker has not contacted the fintech giant directly to present their demands.

Advertisement. Scroll to continue reading.

“Revolut has not received any direct contact or demand from the individuals or group making these claims,” a Revolut spokesperson said, responding to a SecurityWeek inquiry.

IAmNotAVillain also said publicly that a sample of the exfiltrated information was in the hands of a former associate who also claimed responsibility for the data breach.

680 Revolut customers, 147GB of police data

The Duel investigations team has established contact with the threat actor and learned that Revolut responded to the fake government requests for roughly five months, Hudson Rock reports.  

The campaign started after the hacker compromised a government employee’s accounts via an infostealer infection and started using the email account to send fraudulent government requests to Revolut Bank UAB, the Lithuania-based subsidiary of the British firm.

According to the hacker, Revolut Bank UAB responded to their requests without questioning their legitimacy.

SecurityWeek understands that the personal and financial information of approximately 680 Revolut customers, reportedly cryptocurrency whales, was compromised.

In separate communications, the hackers claimed that their campaign lasted for six months and that it also involved the theft of over 147GB of data from a law enforcement agency in Italy. The Italian police have launched an investigation into the matter.

The compromised email address on pec.interno.it appears to belong to an employee within the Italian Ministry of the Interior. Hudson Rock says it is aware of more than 300 compromised credentials associated with pec.interno.it.

“Based on this intelligence, we assess that it is highly unlikely the hacker actively infected these specific employees themselves. Instead, they likely purchased or utilized existing Infostealer logs containing these credentials, attempting to obfuscate their true method of initial access,” the cybersecurity firm notes.

Related: First Agentic AI Data Breach Reported to Spanish Regulator

Related: 280,000 Impacted by Premier Medical Group Data Breach

Related: Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

Related: 240,000 Hit by Data Breach at Japan’s Digital Agency

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/revolut-data-breach-5-months-680-high-profile-accounts-3m-ransom/