Three hundred thousand dollars, negotiable, in Monero or Bitcoin. The archive costs so much with data from 700 Revolut customersaccording to an announcement that appeared on September 23 on a forum frequented by cybercriminals. The advertisement bears the signature of IAmNotAVillainthe group that claims the coup against British fintech. The French site FrenchBreaches documented it, which states that it cannot verify whether the lot is authentic, complete and up-to-date. A week ago the price was ten times higher, and the bank should have paid it.
One tenth of the first request
Before the ultimatum there had been serial dossiers. In the days following the discovery of the scam, as International Cyber Digest had reported, the group began to publish sensitive customer data. Among these were well-known names such as the tennis player Alexander Shevchenko And Felix Romerhead of the Gamdom and Skins.com platforms. The stated goal was a payment from Revolut. The threat was to spread more messages, more data and details about the internal work of the bank team. The hackers then accused the fintech of having transferred sensitive information to countries outside its jurisdiction and of having handled privacy with negligence. The pulpit, it must be said, is not the most credible.
@International Cyber Digest /
The September 16th the ultimatum has arrived, published online complete with a countdown: 6,000 Monero, around 3 million dollars, to be paid within 24 hours. Otherwise the data would have ended up being sold to other criminal organizations. This was reported by the Financial Times, to which the authors had also sent a sixty-second video in which they scrolled through passports, driving licences, verification photos and transaction histories. Revolut has always maintained that it has not received any direct contact or requests. The deadline expired without public responses, and the price list was adjusted. In the announcement of September 23 the seller describes the goods with the precision of a catalogue. There are front and back ID documents and selfies used for recognition. There are contact details, bank details and the history of transfers, deposits and withdrawals, including movements in cryptocurrencies. The group presents the clients involved as high-net-worth individuals, the so-called cryptocurrency whales, and claims to also have some well-known names on its file. On the word, of course.
The message to customers
Then there is the last move, which changes the nature of extortion. According to reconstructions in the Italian press, the group has opened a leak site on the Tor networkwith the faces, documents and bank details of about ten account holders. Through new channels, Telegram now addresses the customers involved directly, with the promise of returning the data to those who pay and not spreading it further. The bank, in other words, exits the role of interlocutor. Hundreds of wealthy people take his place, each with their bank statements in the hands of the blackmailers.
From the PEC of Reggio Calabria to the Guarantor
No one, it should be remembered, broke into Revolut’s servers. As we told you, it was the bank itself that delivered the data. On September 12, in a statement to TechCrunch, Revolut admitted that it had received fraudulent requests from an email address belonging to the legitimate domain of a government agency and that it had passed on sensitive information to an unauthorized third party. He called it a sophisticated impersonation scam and assured that customers’ systems and funds were not touched.
The hackers gave their version to the Financial Times. For months they would have passed themselves off as Italian law enforcement agencies and would have used PEC. The targets were the so-called cryptocurrency whales, chosen in advance with blockchain analysis. The compromised mailbox belonged to the Prefecture of Reggio Calabria, and the Calabrian prosecutor’s office opened an investigation. The Postal Police and the National Anti-Mafia and Anti-Terrorism Directorate also deal with it. The group then claims to have stolen 147 GB of data attributable to the Interior Ministry, although so far no official verification has confirmed this.
On 18 September the Guarantor for the protection of personal data intervened. He asked the banks to search their systems for “anomalous” communications arriving from the same inbox. It then started an exchange of information with the Lithuanian authority, because the main company of the Revolut group is based in Lithuania, and consulted the Ministry of the Interior to understand if other institutions had been affected. In the note, the Authority writes that the affair has highlighted “some weak sides” of the official PECs. We will see in the next few days how the story will continue.