Markets by Trading view

Revolut Breach Escalates as Attackers Threaten to Release More Customer Data

Facebook
Twitter
LinkedIn

Revolut’s data breach has moved into a much more uncomfortable phase.

Just two days after Disruption Banking reported that Revolut had handed over passports, verification selfies and customer account histories following a fake government request, the group behind the attack is now reportedly releasing customer information and demanding payment.

According to CoinDesk, the attackers are threatening to release more data unless Revolut pays. The reported demand is 10,000 Bitcoin.

That number should be treated carefully. Revolut has not confirmed the ransom demand and there is no independent confirmation that the entire dataset being circulated is genuine. But the underlying problem is real.

Customer information has apparently left Revolut. And someone is now threatening to keep publishing it.

This was never a conventional hack

The original incident was unusual because the attackers did not need to break into Revolut’s banking systems. They persuaded Revolut to give them the information.

As Revolut confirmed, an unauthorised third party used an email account on a legitimate government agency domain to submit fraudulent requests for customer information.

The requests passed the relevant authentication checks. Revolut treated them as genuine. The information was then released.

As we reported previously, that information may have included names, dates of birth, addresses, passports and driving licences, verification selfies, IBANs, account statements, withdrawal records and full transaction histories, including Bitcoin activity.

Revolut says its systems and customer funds were not compromised. That is important. But it is not the same as saying the incident is not serious.

The data is the asset

A password can be changed. A card can be cancelled. A passport, home address and financial history are different. Put those pieces together and you have a potentially valuable package for fraudsters.

The crypto element makes the situation more interesting still.

A customer identity linked to Bitcoin transaction activity can tell an attacker considerably more than a conventional leaked email address. It can potentially connect a real person to an on-chain financial history.

That is why the latest developments matter.

This is no longer just a story about how a fake government request got through Revolut’s controls. It is now a story about what happens when the information obtained through that failure becomes a bargaining chip.

Then came the ransom

The reported demand for 10,000 BTC is eye-catching. At current prices, that would be worth billions of dollars.

The important question is not whether the attackers really expect to receive 10,000 Bitcoin. It is whether they have enough genuine information to make continued publication painful for Revolut and its customers.

Reports circulating online suggest that the group has already started publishing information allegedly belonging to affected customers. There are also suggestions that the attackers may have focused on high-net worth individuals.

That would make the dataset potentially more valuable even if the total number of affected customers is relatively small.

This is a risk management problem

For investors, this is where the story gets more interesting. Revolut has more than 80 million customers and banking permissions across more than 30 countries. The company is no longer simply a fintech app competing with traditional banks. It is becoming a major financial institution.

That means operational failures increasingly have to be judged in the same way as they would be at a much larger bank.

How did the request get through? Was there a second level of verification? Who had authority to release the information? How many customers were affected? Which legal entity handled the request? And how did an unauthorised person gain access to an account operating on a legitimate government domain?

Those questions remain unanswered.

The bigger problem for Revolut

There is an uncomfortable distinction at the centre of this story. Traditional cybersecurity is designed to stop unauthorised people getting into your systems.

This incident appears to have involved an attacker convincing the institution that they were authorised in the first place. That is harder.

It is also becoming more relevant as financial institutions deal with increasingly sophisticated impersonation attempts. The attacker does not necessarily need to defeat the technology. They may only need to defeat the person operating it. That is a very different type of vulnerability.

What happens now?

Revolut says it has blocked the relevant email address and notified the government agency involved, law enforcement, data protection authorities and financial regulators. It has also contacted the customers it believes were affected.

But the latest developments create a new set of questions. Can Revolut establish exactly what information was taken? Can it stop further publication? How many customers are actually affected? And what happens if the attackers start demonstrating that they have more data than initially believed?

The reported 10,000 BTC demand may ultimately prove to be a sideshow.

The real issue is whether Revolut has lost control of sensitive information belonging to its customers. For a company whose business is built on trust, that is the part investors should be watching. Because customer money may still be safe. Customer data may be a different story.

See Also:

Revolut Handed Passports and Account Histories to a Fake Government Request | Disruption Banking

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.

Related Posts

Write your email to verify subscription

Loading...

Sign up for our free newsletter and receive the latest banking and fintech stories, straight to your inbox - every week