- UK bank Revolut disclosed a second customer data breach this month after former broker DriveWealth suffered a social engineering attack on Sept. 4-5.
- Compromised data included names, emails, ages, genders, citizenship information, postal addresses, and employment details.
- The earlier Revolut breach involved an Italian government email and prompted ransom demands ranging from $760 million in Bitcoin to $3 million in Monero.
- The Hacker published the “Italy Files” with data on 680 crypto whales and is now selling the data at a steep discount.
On Sept. 24, UK bank Revolut revealed that customer data was breached twice this month after its former third-party US broker, DriveWealth, suffered a social engineering attack.
The breach, disclosed by both firms, occurred on Sept. 4 and Sept. 5 and, according to reports, exposed names, emails, ages, genders, citizenship information, postal addresses, and employment details.
DriveWealth‘s breach data does not include affected European Economic Area customers past 2023. Neither company disclosed how many users were impacted or what happened during the social attack.
However, Revolut stressed that core infrastructure, funds, and accounts were not impacted. Earlier this month, Revolut revealed that Hackers used an Italian government email to access company data.
Ransom demands following that email attack reportedly ranged from $760 million in Bitcoin to $3 million in Monero later. The hacker now claims that “negotiations didn’t go as planned” and has published the “Italy Files,” which include data from 680 crypto whales.
Journalist Jason Mikula noted that the hacker is selling the data 10 times cheaper than their ransom, suggesting “the group is struggling to monetize the data they have exfiltrated.” The hacker is also offering impacted users, including Mt. Gox CEO Mark Karpelès, the opportunity to pay to prevent their information from being leaked.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
