HomeNews
Share

"The blood will be on your hands": Hackers demanded $3 million from Revolut in exchange for customer data

After the ultimatum was published, the attackers sent the FT a video allegedly showing stolen passports, driver's licenses, and customers' transaction histories

Albert Fahrutdinov

Albert Fahrutdinov

reporter Oninvest
Hackers demanded $3 million from Revolut, threatening to sell customer data obtained in a data breach / Photo: Dargog/Shutterstock.com

Hackers demanded $3 million from Revolut, threatening to sell customer data obtained in a data breach / Photo: Dargog/Shutterstock.com

Hackers claiming responsibility for the leak of Revolut customer data have demanded a $3 million ransom from the neobank and given it 24 hours to pay, according to the Financial Times. The ultimatum from the group iamnotavillain appeared on its website on the afternoon of September 16; the amount was specified in the cryptocurrency Monero—6,000 XMR. The attackers are threatening to pass the information on to other criminal groups: “Otherwise, all the data will be sold, and the blood will be on your hands.”

That evening, Europe’s most valuable startup stated: “Revolut has not received any direct communications or demands from the individuals or group making these claims” (as quoted by the FT).

The group told the newspaper that it had made its demands via the website for the first time and had not yet negotiated with Revolut. The FT calls this approach “unusual”: typically, extortionists first contact the victim privately and only go public with the matter if the victim refuses to pay or make contact.

Passports for Sale

Shortly after the ultimatum was published, hackers sent the FT a one-minute video showing an unidentified user reviewing documents allegedly obtained from Revolut. According to the video, these documents include driver’s licenses, passports, and photos used to verify customers’ identities, as well as transaction histories, the newspaper reports.

According to the FT, the data breach affected at least 680 customer accounts, and those affected are concerned about the disclosure of their personal information. Revolut previously stated that it is providing them with prompt assistance and is “working closely with the relevant law enforcement and regulatory authorities,” the newspaper notes.

Posing as government officials

Revolut first confirmed the data breach on September 11. According to the hackers, they gained access to Italian government email accounts and, posing as law enforcement officials, requested customer information from the neobank. A source speaking to the newspaper confirmed that the correspondence, which spanned several months, took place via PEC—a certified email system. Revolut stated that its own systems and databases had not been compromised.

The group claims that it targeted customers with large cryptocurrency holdings using blockchain analysis. As The Wall Street Journal reported, Revolut customers fear “wrench attacks,” in which criminals use threats of violence to force Bitcoin owners to grant access to their funds.

Among those affected is crypto entrepreneur Felix Römer. According to the WSJ, the scammers obtained his home address, a photo of his passport, and his Revolut account transaction history. “If you have cryptocurrency and your address has been compromised, it’s essentially an invitation to be robbed,” he told the newspaper.

A data breach affecting hundreds of Revolut customers occurred as the neobank was actively expanding into Western markets / Photo: Veja/Shutterstock.com

Hack of the Italian State Post Office, the Hunt for "Whales": The FT Learns Details of the Revolut Data Breach

This article was AI-translated and verified by a human editor

Share

Trending

Stock Screener
Buy
Sell






















Small Caps
Investment and Finance News