An explosive Financial Times report has brought to light a serious data breach at Revolut, revealing that 680 customers of the fintech giant were affected by fraud. The hackers behind the breach threatened to sell confidential records belonging to hundreds of customers unless the British fintech paid a $3 million ransom within 24 hours.
Read: Subscription-based deposit accounts with exclusive perks: What each bank is offering
The group, which calls itself iamnotavillain, published the ultimatum on its website Wednesday afternoon alongside a digital countdown clock. According to the Financial Times report, Revolut has reached out to 680 customers who, based on the company’s initial investigation, are believed to have been affected by the incident and had their personal data compromised.
Financial Times: What we know about the hackers demanding $3 million from Revolut
The email message told Revolut to pay “6,000 XMR / $3,000,000… otherwise all data will be sold and the blood will be on your hands.” XMR is the Monero cryptocurrency, which is particularly popular among hackers due to the difficulty of tracing its transactions.
The report indicates that Italian hackers are believed to be behind the threats. They allegedly used a compromised Italian government email account, posing as government officials requesting access to customer data.
How the hackers carried out the attack
Using this method, the hackers were able to obtain data including residential addresses, identity verification photographs, identification documents, and information relating to customers’ Bitcoin activity.
A Revolut spokesperson stated that the company recently identified a “sophisticated external impersonation fraud,” in which an unauthorized third party used a legitimate government agency email domain to submit fraudulent information requests.
The company confirmed that once the incident was detected, it immediately blocked the specific address, notified the relevant regulatory authorities, and contacted all affected customers. Revolut also assured that its systems and customers’ funds remained fully unaffected.