Revolut handed data to someone posing as an Italian regulator — The National
British fintech company Revolut confirmed that it handed over private customer data to a person who posed as a representative of an Italian state regulator in email correspondence. As The National reports, the attacker obtained data from identity documents, photographs, account statements, transaction histories and other information.
The incident reportedly may have affected about 650 customers of the service. Revolut has more than 80 million customers. The company did not respond to The National's request for comment.
Trust in a government domain
Ivan Milenkovic, vice president of cyber risk technology at Qualys, said that the attackers did not breach Revolut's systems: they sent a data request that company employees fulfilled. According to him, to pose as law enforcement officials, the attackers compromised the Italian government's email system.
The expert called the possible leak of passports, driver's licenses and verification selfies particularly dangerous. Unlike a password, such identity and biometric data cannot be replaced quickly.
More current news is available on the UA.News Telegram channel Telegram.
Extortion reports
A representative of cyber threat analysis company Acronis noted that the incident could have escalated into extortion. According to separate reports, the attackers may have disclosed the stolen data and demanded about $3 million in cryptocurrency from Revolut. At the same time, Revolut said it had not received a direct ransom demand.
Delinea CEO Art Gilliland stressed that employees should not be the last line of defense in such cases. He urged companies not to consider a genuine government domain sufficient proof of a request's legitimacy, but to independently verify sensitive requests, introduce approvals, and restrict access to data and the volume of information that can be transferred.
Similar social engineering methods
Writer Joan Westenberg also described a social engineering attempt disguised as a podcast invitation. She was sent a link and asked to run a command in the terminal allegedly to install webinar software, after which she stopped communicating.
The Acronis representative called this an example of ClickFix-style social engineering, in which a victim is persuaded to run malicious software under the pretext of installing an application or fixing a technical problem. According to him, there are no signs that artificial intelligence was used in this specific case, but such technologies make similar attacks cheaper, faster and easier to scale.