The Revolut data breach has come under scrutiny in Cyprus, with the company formally notifying the Office of the Commissioner for Personal Data Protection about the incident.
The Cypriot authority is now assessing the breach within the scope of its responsibilities. Revolut says on its website that it has 450,000 customers in Cyprus.
Economy Today contacted the office of Data Protection Commissioner Maria Christofidou, who confirmed that Revolut had also notified those affected by the breach and provided them with information about the steps they should take.
Revolut notified affected customers
“Regarding the personal data breach involving Revolut customers, the company notified the Data Protection Authority of the incident. The notification is being assessed by the Authority within the scope of its responsibilities. It is noted that the company has informed the affected individuals about the breach and the steps they should take,” Christofidou told Economy Today.
It is not yet known how many Revolut customers in Cyprus, if any, are among those affected.
Economy Today has also contacted the office of Commissioner of Communications Marios Pieris and the Cyprus Securities and Exchange Commission and is awaiting further information.
How the breach happened
The case concerns a personal data breach that emerged in recent days and has raised international concerns over the security of personal and financial information. Revolut has more than 80 million customers across over 30 countries.
On 12 September, Revolut confirmed the breach of sensitive customer data to Reuters. Fraudsters appear to have posed as government or law enforcement officials and submitted fraudulent requests to Revolut for customer information.
According to the Financial Times, those responsible compromised an Italian government email system and used it to impersonate law enforcement officials.
The exposed data reportedly includes personal information, passports, driving licences, identification photographs used as part of Know Your Customer (KYC) procedures, as well as account information and financial transaction histories.
International media reports indicate that at least 680 customer accounts were affected, with authorities examining the Revolut data breach.
Hackers reportedly demand $3m ransom
On 16 September, the Financial Times reported that a hacker group calling itself “iamnotavillain” was demanding a $3m ransom, threatening to sell the personal and financial information of hundreds of Revolut customers to other criminal groups if the money was not paid within 24 hours.
The Irish Times, citing information from the Financial Times, reported that the hackers were demanding payment in Monero (XMR), a cryptocurrency designed to provide increased transaction privacy.
Revolut said that, as of Wednesday evening, it had not received any direct communication or ransom demand from the individuals or group making the claims.
Also read: E-scooter laws face enforcement concerns
For more videos and updates, check out our YouTube channel


