Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
Attackers who exploited a fake government request to access Revolut customer records have made their first move.
ByJose Oramas
Attackers who tricked Revolut into handing over customer records published the data of high-profile clients over the weekend and demanded a ransom of 10,000 Bitcoin, warning on September 14 that they would leak more each day until the European fintech pays.
Revolut confirmed on September 12 that an unauthorized party had impersonated a government agency, sending fraudulent requests for information from an email on the agency’s real domain with valid technical authentication, which staff processed as a routine legal request.
Revolut Blocks Address and Alerts Regulators
As CryptoPotato covered, the data breach included the disclosure of passports, verification selfies, account statements and IBANs, alongside names, dates of birth and home addresses. A Revolut spokesperson said the company “recently identified a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information.”
The group calling itself Revolut Smilik posted client files across several Telegram channels and warned it would “start releasing more and more data every day until Revolut pays for leaking their customers.”
https://x.com/visegrad24/status/2099467072547791057
The posted material appeared to include data on high-profile individuals, among them company executives, sports professionals, and performing artists which put the 10,000 Bitcoin demand at more than $782 <a href="https://xpertsstudio.com/u-s-doj-seeks-61-<a href="https://xpertsstudio.com/bitmine-buys-68m-in-ethereum-nears-6-million-eth/” title=”BitMine Buys $68M in Ethereum, Nears 6 Million ETH”>million-in-what-it-calls-irans-crypto/” title=”U.S. DOJ seeks $61 million in what it calls Iran's crypto”>million. Revolut declined to comment on the ransom
The company said it blocked the address on detection and alerted the relevant government agency, law enforcement, data protection and financial regulators, and that its systems and customer funds were unaffected. Revolut said a limited number of customers were affected and that it had contacted them directly, without disclosing a figure or naming the compromised agency.
Source: cryptopotato.com
