Hackers demand $3m from Revolut over customer data

Date:

The Revolut data breach has raised concerns in Cyprus, where the fintech has around 450,000 customers, after hackers began publishing information allegedly obtained in the incident.

According to a 14 September report by Blockonomi, cybercriminals have started releasing customer data and are demanding a ransom, threatening to publish more information if their demands are not met.

A hacker group is reportedly demanding $3 million from Revolut, threatening to sell personal and financial data belonging to hundreds of the fintech’s customers if the ransom is not paid within 24 hours.

Hackers demand 6,000 Monero

The group, which calls itself “iamnotavillain”, published the ultimatum on its website alongside a digital countdown.

According to the Irish Times, citing information from the Financial Times, the hackers are demanding 6,000 Monero (XMR), which they value at around $3 million.

Monero is a cryptocurrency designed to provide increased privacy for transactions.

What information was exposed

The compromised information may include names, email addresses, dates of birth, occupations, residential addresses and telephone numbers. Reports also indicate that identity documents, including passport and driving licence images, as well as bank statements and IBANs, may have been exposed.

Revolut has said the number of affected customers is small. Current reporting indicates that about 680 customers were affected by the incident. The company has also said that customer funds and its internal systems were not compromised.

According to the Financial Times, the attackers allegedly compromised an Italian government email system and used it to impersonate law enforcement officials.

Ransom demand and further leaks

The attackers are reportedly demanding a ransom and have threatened to release additional stolen information if their demands are not met. Materials linked to the breach have already been published, according to reports.

There are also concerns that affected customers could be targeted in follow-up phishing attempts. Reports suggest criminals may send emails containing links that ask recipients to verify personal information.

Revolut advises customers who notice suspicious activity to report it through the company’s official support channels.

Public ransom demand

The hackers’ decision to publicly issue the ransom demand is unusual. In similar cases, cybercriminals typically attempt to negotiate privately before publicising an attack if no response is received.

“Iamnotavillain” told the Financial Times that this was the first time it had used a public website to issue a ransom demand and claimed that no negotiations with Revolut had taken place at that point.

Revolut, which began operating in 2015, currently serves around 80 million customers and operates as a bank in more than 30 countries.


Also read: Solidarity Fund budget sets €28.7m for beneficiaries
For more videos and updates, check out our YouTube channel

Share post:

Popular

More like this
Related

Mediterranean warming and becoming saltier at faster rate

The Mediterranean Sea is becoming warmer and saltier at...

School bus cancellations in Laranca leave pupils stranded

Repeated school bus cancellations in the Larnaca district are...

JYSK expands into Cyprus, first stores to open in spring 2027

Danish home furnishings retailer JYSK is entering the Cyprus...

Hands Across the Divide marks 25 years

Hands Across the Divide (HAD), Cyprus’ first bicommunal women’s...