A certified email address, stolen six months earlier, was enough to convince a digital bank worth billions to hand over the passports, residential addresses and banking movements of hundreds of people. This is what happened to Revolutthe English company has become over the years a competitor of the large traditional European banks, which was fooled by a group of cyber criminals and ended up passing on the data of almost 700 customers to them.
The deception of the police email
The attack did not have to violate Revolut’s IT systems, because the creators only had to introduce themselves, at least according to what the managers themselves told the International Cyber Digest website, with an official certified email address of the Italian police forcespreviously compromised. With that account they sent to Revolut’s Lithuanian headquarters a request that seemed to come from an investigation by the Milan prosecutor’s officeasking for information on a large number of customers. The domain was authentic, the request formally motivated: Revolutfaced with such a large amount of data, nor contacted the police directly for a counter-verification. He simply replied, and sent everything.
Revolut’s version
Revolut called the episode a “sophisticated scam” and said it immediately notified the customers involved, as well as law enforcement, data protection authorities and financial watchdogs. The company claims that its systems have not suffered any direct violations and that not a single euro has disappeared from its accounts. The fact remains that the data, yes, has come out: among the information that ended up in the hands of hackers there are name, date of birth, profession, address, contact details, copy of passport or driving license and the facial image collected when opening the account. Revolut clarified that actual biometric data would not be involved.
Who are the customers involved
The group that claims responsibility for the attack calls itself IAmNotAVillain and has opened a site to publicize the stolen material, also spreading some extracts on Telegram. According to what the hackers themselves declared to International Cyber Digest, the majority of the customers involved were Swiss and French, but the data also includes residents of around thirty other countries, from Italy to the United Kingdom. Among the names that have emerged are Barcelona footballer Georges Mikautadze, Kazakh tennis player Alexandr Shevchenko and, according to the Financial Times, former Mt. Gox CEO Mark Karpelès. The number of people affected, 680 according to sources gathered by some specialized newspapers, has not been confirmed by Revolut. The hackers, in the meantime, are demanding a ransom of 10 thousand bitcoins, approximately 673 million euros at the current exchange rate.
The claim: six months of access and 147 gigabytes stolen
The hackers claim to have started the operation six months ago, compromising an account with the @pec.interno.it domain belonging to the Italian police forcesprobably to the police. From there they allegedly stole 147 gigabytes of material, including internal documents, diaries and employees’ personal information. Some have released a demonstration screenshot of email headersalso reported by International Cyber Digest.
@International Cyber Digest /
Neither the Ministry of the Interior nor the National Cybersecurity Agency have released statements on the matter.
The legal instrument used as a Trojan horse
The mechanism used has a technical name, European Investigation Order, and is the instrument provided for by a 2014 European directive which obliges banks to provide data to law enforcement agencies and government bodies of other member states. Precisely the automatism of that obligation, designed to speed up judicial cooperation between EU countries, became the flaw that allowed the theft.