Revolut Breach Exposes High-Risk Customers, Raises Personal Safety Concerns
By CU Today Staff —
LONDON—A hacker who obtained sensitive customer data from digital financial platform Revolut targeted high-net-worth and cryptocurrency figures, raising concerns that the breach could put some victims at risk of kidnapping, extortion and other physical threats, according to Bank Info Security.
Bank Info Security reported Revolut confirmed the breach after notifying affected customers Saturday, saying attackers used a legitimate but compromised government email account to submit fraudulent requests for customer information.
“Fraudsters exploited a legitimate government email domain that passed Revolut's technical authentication checks - SPF/DKIM/DMARC - to send deceptive information requests,” threat intelligence firm Kela said, according to Bank Info Security.
Kela said Revolut employees, believing the requests were legitimate government orders, manually released sensitive files for a limited number of customers.
Revolut said its systems were not breached and no customer funds were stolen. But exposed information included names, contact details, bank account and cryptocurrency wallet information, transaction records and copies of know-your-customer documents, including passports, driver's licenses and selfies. Bank Info Security cited the Financial Times as reporting approximately 680 customers were affected.
Bank Info Security reported the hacker claimed to have compromised a system used by Italian federal agents and then used access to a government email account to socially engineer Revolut into providing customer records. The apparent focus on cryptocurrency owners has heightened concerns about physical security.
“Lives are now at risk. I'm personal friends with one of the victims, and he'll probably have to move houses due to the continued (credible) kidnap threats,” a Duel.com employee known as Korra said, according to Bank Info Security.
Bank Info Security reported several prominent cryptocurrency figures said they were affected, including former Mt. Gox CEO Mark Karpelès, cryptocurrency entrepreneur Marc Zeller and Gamdom founder Felix Romer. Romer said some victims had been targeted for extortion before Revolut disclosed the breach.
“Already two months ago me and others started to get blackmailed with the compromised data,” Romer said.
The hacker subsequently created a public data-leak site advertising stolen KYC records and cryptocurrency and fiat transaction information, but Bank Info Security reported the site was offline by Tuesday.
Originally reported by CU Today.