Tech

Revolut Faces Extortion Threat After Hackers Steal Customer Data

The digital banking giant said over the weekend a “very limited” number of customers had been affected by an impersonation scam, which compromised data including customers’ identity documents, postal and email addresses, facial verification image and phone numbers. In messages to City AM on Monday, the hacker group, calling itself Revolut Smilik, confirmed it is seeking payment from Revolut and would release “more and more data everyday” if it did not pay. 

Several notable figures have already had their data released, according to the messages. Affected Revolut customers received an email over the weekend that confirmed their account statements, withdrawal records and full transaction histories had also been released. The company and the hackers are yet to have direct contact, City AM understands. 

Revolut was targeted in a “sophisticated external impersonation scam” where hackers used a legitimate government agency email to submit fraudulent requests for information. The company said its core infrastructure, databases and customer accounts had not been compromised. FCA and data watchdog aware of incident. A Revolut spokesperson said: “Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators.” 

The company declined to confirm the number of customers that had been affected or comment on the hackers’ request for payment. A Financial Conduct Authority spokesperson said: “We are aware of the reported incident involving Revolut and are engaging with the firm to understand the impact and the steps being taken to address any potential harm.” A spokesperson for the Information Commissioner’s Office said: “We can confirm we have received a report and are assessing the information provided.” 

Financial institutions are legally required to comply with official law enforcement or government agency requests for information and customer data. Communications from verified addresses are processed as mandatory legal demands, a source close to the bank said. The London-based company has more than 80m customers globally and operates across 30 countries. In the last year alone it has secured licences and approvals from regulators in the UK, France, US and UAE. The firm began a secondary share sale earlier this year that is expected to value it at $115bn.

Culled from https://www.cityam.com/ 

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button