Revolut hackers demand $3 million as breach exposes crypto holders' data

As stated by the Financial Times (FT), the attackers who duped Revolut into giving up customer data are asking for a ransom of $3 million to ensure that the information remains confidential. The information includes identity documents, home addresses, and transaction records related to crypto-heavy accounts. The ransom is just one of the problems. The stolen data could connect visible on-chain wealth to a real person. For Revolut, which has just received a conditional approval for forming a national bank, the incident raises a larger question: how does the centralized financial system protect its KYC data? A Monero ransom and a threat to leak According to the report in the Financial Times, the group, calling itself “iamnotavillain,” demanded $3 million in Monero and threatened to sell the records if Revolut did not comply. Reuters said Revolut had received no ransom demand or direct contact from the attackers. One source cited by the news outlet said that around 680 customer files had been compromised in this case, although Revolut has offered no specifics, referring to the number of affected customers only as “limited.” The attackers also claimed to have hacked an email system of the Italian government and performed blockchain-focused analysis to identify customers of Revolut who own a lot of cryptocurrencies, according to a separate report by the FT. Revolut has not confirmed this claim on its own. How the records left Revolut According to Revolut, its core systems and client funds were not compromised. Instead, an email account from the domain of a legitimate government agency was utilized in order to submit fraudulent information requests. The company stated it was a “sophisticated external impersonation scam”, adding that once it got wind of the scam, it blocked the email address. The leaked information included names, dates of birth, home addresses, phone numbers, ID documents, verification selfies, bank statements, and transaction lists. Furthermore, The Block reported that former Mt. Gox executive Mark Karpeles said he was affected by the breach and shared a notification from Revolut saying details about Bitcoin transactions were revealed. “Revolut customers were targeted in a fraudulent emergency data request sent via an email at a ‘government agency.’” — Mark Karpelès According to the on-chain analyst ZachXBT, the attack seemed to be deliberate rather than random. “While the incident is likely limited in size it seems to have been targeted at high net worth users.” — ZachXBT Why exposed KYC becomes a safety problem A leaked address paired with evidence of large crypto holdings can turn a data breach into a physical-security threat. Chainalysis says many violent crypto attacks are premeditated, with victims identified through leaked data, social media, blockchain analysis, or insider information.
عنوان اصلی (انگلیسی): Revolut hackers demand $3 million as breach exposes crypto holders' data
مشاهدهی خبر کامل در منبع ↗ بازگشت به مونرواین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.