Revolut’s Attackers Are Now Leaking Customer…

13

The Revolut data breach has turned from a disclosure into what the attackers are presenting as a live extortion campaign. Actors who obtained sensitive customer records have reportedly begun publishing stolen identity documents and selfies online and are threatening to release more each day until the fintech pays, Cointelegraph reported. “We’re going to start releasing more and more data everyday until revolut pays for leaking their customers,” the attackers wrote on Telegram, according to that reporting.The authenticity of the leaked material, the identity of the attackers and any ransom figure remain unverified threat-actor claims that neither Revolut nor law enforcement has confirmed. Revolut has not said whether it will pay, and has still not said how many people were affected.That escalation is what makes this the second, larger story. The breach was never a hack of Revolut’s own systems; it was a fraudulent request for customer information sent from an email address on a genuine government agency’s domain. Every regulated broker, payments company and exchange answers that same kind of government and law-enforcement request, and most do so without an out-of-band step to confirm the sender is who the domain says they are. The Revolut incident is the latest example of an attack the security industry has documented for years, now escalating in public.

What Changed Today: From Breach to Active Extortion

The disclosure Revolut made on September 12 has become a ransom situation. A cyber-intelligence account, International Cyber Digest, reported on X that the attackers had begun posting customer data and were threatening to release “more messages, data and insights into how the Revolut team operates,” while accusing the company of negligence and of sending data outside its jurisdiction, claims that are the threat actors’ own and that neither Revolut nor law enforcement has confirmed.

Some affected customers have identified themselves publicly, including former Mt. Gox chief executive Mark Karpelès, who said last week that he was among those notified.The exposed data is what makes the threat serious. Revolut confirmed to TechCrunch that the information may include full names, dates of birth, occupations, postal and email addresses, phone numbers, passport and driving-licence copies, and verification selfies, along with account statements, IBANs and full transaction histories, including records of Bitcoin activity.Passwords can be reset and accounts secured, but a passport scan, a facial-verification image and a history linking a real identity to crypto transactions cannot be changed after the fact, which is precisely why the material has extortion value. Revolut has said its systems and customer funds are unaffected and that a “limited” number of customers were hit, a number it has declined to specify even as the leaks begin.

Investor Takeaway

This is now an extortion event, not a contained disclosure: with attackers publishing data on a daily schedule, the exposure grows until they stop, which puts pressure on Revolut to respond publicly rather than manage it quietly.

The Vector: A Real Government Domain, a Fake Request

The mechanism is the part every regulated firm should study. The attacker did not break into Revolut’s database; they emailed a request for customer records from an address on a legitimate government agency’s domain, and the correspondence passed internal checks because it came through the agency’s real infrastructure.Revolut later determined the sender was unauthorized, blocked the address, and notified the agency, law enforcement, data-protection authorities and financial regulators. It has not named the agency or said how the account was used, which leaves open the question of whether the same sender approached other institutions.This is a known technique with a name: the fraudulent emergency data request, or fake EDR. It exploits the fact that authenticating a request’s domain says nothing about who was actually typing, the same principle behind the impersonation scams increasingly used by state-backed actors to infiltrate Western companies.

Why This Is an Industry Problem, Not a Revolut Problem

The fake-EDR vector has a documented history across the largest technology platforms. In 2021, attackers affiliated with the Recursion Team and Lapsus$ groups, several of them teenagers, used forged emergency requests sent from hacked police and government accounts to pull user data out of Apple, Meta and Discord, as Brian Krebs and Bloomberg documented. The FBI issued its own alert in November 2024 warning of a spike in hacked police emails and fraudulent data requests submitted to US companies. None of the firms caught out were inexperienced at handling law-enforcement requests; they all had policies, and the requests still worked.The emergency channel is built for speed, an imminent-threat claim, often no court order, a response expected within hours, and every speed optimization is a verification gap. There are roughly 18,000 law-enforcement jurisdictions in the United States alone, each a set of email accounts, and one compromised account anywhere is enough. Because each company verifies in isolation, the same fraudulent requester can approach fifty firms and each sees a first-time contact with no history.A fake EDR only has to work once; verification has to work every time. That asymmetry is why the incident is a warning to every regulated broker, PSP and exchange, and it lands as Revolut expands into US banking and stablecoins after securing preliminary approval for a national bank, a business built on holding exactly this kind of identity and transaction data.

Investor Takeaway

The concrete mitigations exist today: out-of-band callback verification to a published agency number, logging and cross-checking of every request, and pooled intelligence across firms are already in use.

Close
Your custom text © Copyright 2020. All rights reserved.
Close