A group claiming responsibility for the Revolut customer data breach has asked for 6,000 XMR, worth about $3 million, within 24 hours, and says it will otherwise offer the records to other criminal groups, the Financial Times reported on Wednesday. A countdown clock ran beside the demand, which went up on the group’s website Wednesday afternoon, Reuters reported, citing the FT. A Revolut spokesperson told Reuters the company has had no direct contact with the group and has received no demand from it directly.
Going by “iamnotavillain,” the group told the newspaper it found its roughly 680 targets by combing blockchain data for Revolut users with big crypto balances. “I rather not disclose my exact way of getting it, but it was via onchain analysis,” the group said, and called the people it went after “crypto whales.” Switzerland and France account for most of them, according to the group; the rest are spread across 31 other countries, among them the U.K., Germany and Spain. A person familiar with the matter put the number of affected customers at about 680, Reuters reported.
Italy Opens an Inquiry
Prosecutors in Reggio Calabria have opened an investigation into suspected unauthorized access to the certified email account of the city’s prefecture, which was reportedly used to send requests signed as Italy’s postal police from an interior ministry domain over several months, Italian news agency ANSA reported. Investigators have not established whether the account was breached or cloned. Italy’s national anti-mafia and anti-terrorism prosecutor’s office is also following the case.
Italy’s data protection authority told the data protection officers of Italian banks to check their own systems for similar intrusions and contacted its counterpart in Lithuania, where Revolut has its main legal seat, according to ANSA. The group also claims to hold 147 gigabytes of data, including Italian police documents and officers’ chats, a claim that is being checked, according to ANSA.
Revolut and U.K. Regulators Respond
Revolut confirmed last week that it handed customer information to an outside party that had “utilised a legitimate government agency domain email to submit fraudulent requests for information.” Passports were among the records handed over, and verification selfies and transaction histories, including bitcoin activity, may have been too, as Unchained reported.
“Revolut systems and customer funds are unaffected,” the company said at the time.
A spokesperson for the U.K. Financial Conduct Authority said in a statement reported by City AM that the regulator is “engaging with the firm to understand the impact and the steps being taken to address any potential harm,” and the Information Commissioner’s Office said it has received a report and is assessing it.
Related Listen: Why the AI Business Model Is Cracking and How Crypto Could Help Fix It
