2 min Security

Revolut data breach affects 680 customers; systems were not hacked

Revolut data breach affects 680 customers; systems were not hacked

Revolut says it has had no direct contact with the group claiming responsibility for the recent data breach at the fintech company. The attackers are reportedly demanding three million dollars and threatening to sell data from hundreds of customers to other criminals.

According to Reuters, which cites reports from the Financial Times among other sources, Revolut’s core infrastructure, databases, and customer accounts were not hacked. A source familiar with the matter says the data breach affects approximately 680 customers.

The incident occurred after Revolut received fraudulent information requests originating from a legitimate government agency email domain. As a result, sensitive customer information was provided to an unauthorized third party. Revolut announced the data breach last Saturday.

Threat to sell data

A group calling itself iamnotavillain claims responsibility for the data breach. On Wednesday afternoon, the group posted an ultimatum on a website, along with a digital countdown clock. If Revolut does not pay $3 million within 24 hours, confidential customer data would be sold to other criminal groups. The group told the Financial Times that this is the first time the website has been used to make such demands. No negotiations with Revolut have reportedly taken place yet.

Revolut confirms this. A spokesperson told Reuters that the company has had no direct contact with the individuals or group claiming responsibility. Revolut also states that it has not received a direct ransom demand from them.

No breach at Revolut

This distinguishes the incident from a data breach in which attackers directly penetrate an organization’s systems. According to Reuters’ source, Revolut’s own infrastructure, databases, and customer accounts were not compromised in this case. The data was exposed because the company responded to fraudulent requests sent via a legitimate government domain. Inadequate verification of information requests can also lead to data breaches, as was previously seen at the SVB.