The British fintech company Revolut recently issued a series of messages confirming a data security incident. Attackers impersonated a government body and, through an email address belonging to a genuine government domain, sent the company fraudulent requests for information. Without verifying them, Revolut furnished the attackers with the sensitive details of some clients as instructed.
Revolut stresses that this incident constitutes a sophisticated external impersonation scam. Its own systems and customer funds suffered no impact whatsoever. Furthermore, the attackers did not directly breach Revolut’s production systems through any network attack. As TechCrunch reported on the confirmed breach, only a “limited” number of customers were affected.
Passports and Selfies Both Leaked
The notification Revolut sent to affected clients states that names, dates of birth, addresses, email addresses, phone numbers, passports, driving licenses, and other information were disclosed to the fraud ring. Some reports add that the leak also included the verification selfies (containing users’ faces) used for identity checks. In addition, leaked data included account statements, IBANs, withdrawal records, and complete transaction histories.
Within the complete transaction history there may lie Bitcoin transaction data. Such information can help attackers piece together a fairly complete portrait of a person’s identity and finances. Thereafter, the attackers can mount targeted phishing, identity fraud, or other financial scams against the victim.
Wrench Attacks May Await High-Net-Worth Users
It can now be confirmed that the attackers’ aim was precisely to gather detailed data on Revolut’s high-net-worth clients. Although they cannot directly breach a client’s account to steal funds, they can themselves launch a wrench attack against a target, or sell the data to downstream criminal rings who will do so.
A wrench attack refers to this: a criminal ring with no hacking ability simply buys a $5 wrench. Then it stalks the target and resorts to real-world physical violence, such as kidnapping, beating, home invasion, or death threats, to force the victim to unlock a cryptocurrency wallet, hand over private keys, or transfer away digital assets.
Such attacks have grown alarmingly common in recent years. Cryptocurrency influencers and employees of related firms are frequently targeted. Previously, the co-founder of a well-known cryptocurrency wallet was kidnapped and had a finger severed. This was a means of pressuring the victim’s family to deliver a crypto ransom.
Personal Safety Cannot Be Guaranteed Once Data Leaks
In the real world, once information such as passports, identity documents, and facial selfies is leaked, it cannot be replaced. Consequently, such a data breach carries a long-term risk of identity fraud and targeted scams. For clients whose information has already leaked, the days ahead may demand constant vigilance over their personal safety. After all, one can never be sure that a malicious event such as a home-invasion kidnapping will not one day occur.
At present, Revolut has not disclosed exactly how many clients were affected, the countries or regions where they reside, the name of the impersonated government body, how the attackers obtained authorization for that body’s email, or how long the fraudulent requests persisted.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!