Cyber security

Revolut hands over the details of 700 customers to fraudsters. The Italian lead

The British fintech company has alerted the users concerned. The fraudulent request, which appeared to come from a government body, may actually originate from our country

Adobestock

3' min read

3' min read

Imagine receiving an email from your bank informing you that your personal details, contact addresses, identification documents and financial details (including your transaction history) are now in the hands of a hacker.

This is what happened to several customers Revolut, with the number estimated at just under 700 people. The British fintech company has notified the affected users by email: ‘We are contacting you to inform you of a recent security incident, involving an external identity theft that resulted in some of your personal data being shared with an unauthorised third party.’

Loading...

What happened

Revolut stated that it had received a request to share its customers’ data from an account that appeared to belong to a government body. The company proceeded to forward the requested information, in accordance with the GDPR (General Data Protection Regulation). Under the European regulation, a company is required to disclose its customers’ personal data if the request from the government body is binding, formally legitimate and based on specific legal provisions (such as investigation orders or warrants).

“The procedure for a government agency to request data is called an ‘emergency data request’, and all platforms (social networks, cloud providers) handle dozens of them every day,” explains Marco Ramilli, founder of the Italian cyber intelligence firm Yoroi.

The problem? The person who made the request was not actually a public authority. The hackers were posing as someone else, using an email address that actually belonged to a government body’s email domain and therefore had valid authentication credentials.

“As soon as we identified the potential risk factors, we alerted the relevant authority,” explains Revolut. Law enforcement agencies, data protection authorities and financial regulators were then contacted.

The notice also states that the accounts of users affected by the incident remain secure and that the company has ‘immediately’ blocked the fraudulent address.

The Italian track

Once the case became public knowledge, a storm broke out on the social media platform X. According to documents obtained and shared by ‘I Am Not A Villain’, the Telegram channel believed to be run by the hackers behind the scam, the email address the cybercriminals appear to have gained access to ends with @interno.it. The emails therefore appear to have originated from an Italian institution, although this has not been confirmed. The institution is said to have requested ‘banking and financial information’ relating to accounts held with Revolut Bank UAB, a Latvian company, for the purposes of a European investigation.

Meanwhile, the ‘International Cyber Digest’, an independent organisation reporting on cyber security news, has stated that hackers are sharing the sensitive data they have stolen, including photos. “They want Revolut to pay. They say they will release more messages, data and information about how the Revolut group operates,” the report states.

Among the customers affected by the scam are reportedly well-known figures such as Mark Karpelès, former chief executive of the cryptocurrency exchange Mt. Gox, and the entrepreneur Felix Romer. Romer has reported receiving blackmail threats based on data stolen from Revolut as early as two months before the company contacted users to inform them of the scam. It would appear, in fact, that the hackers had been active for several months – perhaps as many as six.

Loading...

At present, no official statement has been issued in response, either by the fintech company or by Italian institutional bodies.

However, the Postal Police – according to reports – are said to be investigating unauthorised access to a computer system and computer fraud.

The expert has their say

But how was it possible to gain access to an institutional email system? “The email account may have been compromised: there are numerous methods, known as ‘attack paths’, for achieving this result – account takeover,” explains Marco Ramilli. An account takeover is a form of identity theft in which a malicious user manages to gain unauthorised access to someone else’s online account.

The government body that fell victim to this breach may not have realised what had happened because PEC is a ‘type of email typically used for official communications or legal matters and, for this reason, may not be monitored as regularly and consistently as a personal email account’.

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti