Hackers Trick Revolut With Fake Italian Police Emails
Hackers used a genuine Italian government email account to obtain sensitive Revolut customer data, affecting around 680 users across Europe.
Revolut has confirmed that hackers used a legitimate Italian government email address to send false requests to collect sensitive consumer information. Revolut was forced to divulge financial and private data since the attackers posed the requests as legitimate law enforcement investigations.
Selfies, addresses, phone numbers, transaction history, and identity documents were among the leaked data. According to reports, some 680 customers, mostly in Switzerland and France, were affected. Revolut said its financial systems and consumer funds were not compromised.
Hackers Used a Real Italian Government Mailbox
Attackers did not breach Revolut's internal systems to trigger the problem. Rather, they were able to obtain a real Italian government mailbox, which they utilised to pass off fake requests as authentic.
The mailbox used the pec.interno.it domain of the Italian Interior Ministry and belonged to the Prefecture of Reggio Calabria. The Local Authorities office of the prefecture was linked to the account.
A legitimate government communication mechanism was used to deliver the communications. This meant that suspicion was not instantly raised by the sender's domain.
The mailbox was allegedly used by the attackers to send fake European Investigation Orders and other information requests. They asked Revolut to identify the clients associated with the cryptocurrency transaction IDs they submitted.
In our previous discussion, Revolut Shares Customer Data After Fake Government Email, we described how a false government request led to Revolut disclosing private client data.
What Information Did Revolut Share?
According to reports, the attackers were able to access far more than just basic client information. Copies of identity documents, selfies submitted for verification, dates of birth, addresses, and phone numbers were all included.
IBANs, account statements, and transaction histories were among the bank account details included in some customer data. Information on cryptocurrency transactions was also shared. The event was reported to around 680 clients. Customers from 31 other European nations were also impacted, but the majority were in Switzerland and France.
As identity data and financial activity can be accessed simultaneously, the information is highly sensitive. The data might link confirmed identities to particular blockchain activities for clients engaged in cryptocurrency transactions.
Revolut has emphasised that its banking infrastructure was not compromised during the event. The business claims that its internal systems were safe and that customer monies were not accessed. Revolut identified the issue as an external impersonation scam involving false information demands.
Italian Authorities Launch Investigation
Italy is currently conducting an inquiry into the compromised government mailbox. The account's access and subsequent use to submit requests to Revolut are being investigated by authorities.
The incident has also prompted inquiries about whether the same account sent identical requests to other organisations. Giulia Pastorella, an Italian politician, has demanded an explanation for the event and raised questions about the safety of Italy's PEC system.
The case also demonstrates why, in this case, merely verifying an email domain was insufficient. Because the attackers were allegedly using a real government email, the domain was authentic. Therefore, more investigation was required to determine the validity of the specific request.
After identifying the fraud, Revolut blacklisted the email address and informed the relevant authorities and impacted clients. An investigation into the event has also been launched by the UK's Information Commissioner's Office.
Stolen Data Becomes Part of Extortion Attempt
Since the first data disclosure, the incident has progressed. According to reports, the attackers have already made samples available to show that they have authentic customer records and have threatened to reveal more of the data they have acquired.
Former Mt. Gox CEO Mark Karpelès was apparently among those impacted, and his response raised awareness of the kind of information that was disclosed.
However, there are still some unconfirmed data regarding the assailants' broader claims. The inquiry is still ongoing, and Italian officials have not publicly acknowledged all of the hackers' claims.
The immediate focus is now on determining how the government mailbox was compromised, whether similar requests were sent to other companies and how much customer information was obtained before the activity was detected.
If you find any issues in this article or notice missing information, please feel free to reach out at team@etherworld.co for clarifications or updates.
To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.
Related Articles
- $90K Crypto Loss After Chrome Extension Hack
- Liquid Network Loses $320M in Security Breach
- Nasdaq Invests $100M in Kraken Parent Payward
- Trezor Email Breach Sparks Crypto Phishing Fears
- Osmosis Freezes $1.79M After nBTC Exploit
To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.
Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.
Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.
To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.
To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.
If you’d like to support our work, share the content and consider donating at avarch.eth.
Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.