Revolut experiences massive data breach following social engineering attack
Approximately 680 Revolut customers have had their personal and financial data exposed following a sophisticated social engineering attack. Cybercriminals impersonating Italian government officials successfully deceived the fintech company by using a fraudulent electronic mail address, prompting Revolut to unknowingly hand over sensitive information including passports, driver's licenses, residential addresses, and banking records over a period of several months.
The hacker group, identifying themselves as "iamnotavillain," is currently demanding a ransom of $3 million in the privacy-focused cryptocurrency Monero (XMR) under the threat of selling the stolen data. The group has issued a 24-hour ultimatum and provided a video sample of the compromised documents, which reportedly include KYC (Know Your Customer) identity verification materials. The fraud was uncovered only after the company cross-referenced the requests with Italian authorities, who denied any involvement.
The incident is now under investigation by Italian judicial authorities for illegal system access and electronic fraud, while the UK's data protection regulator has been notified. Revolut has initiated communication with the affected customers to manage the fallout of the breach.