Revolut victim of a scam, data of almost 700 customers exposed

There are almost 700 Revolut customers implicated in a mega ‘scam’ that led the fintech to violate personal data and accidentally hand it over to some cyber criminals posing as government officials. This is sensitive information: passport data, identity cards, account numbers, residential addresses and bitcoin activity. This is what the Financial Times announced, revealing that according to some sources, the payments group promptly contacted 680 people it believes were involved in the scam.

According to what Elisabetta Piccolotti of Avs underlines, reporting press indiscretions, “the domain from which the hackers requested and obtained the information would be a PEC of the Italian Ministry of the Interior”. For this reason, the parliamentary group will present a question to Minister Matteo Piantedosi “to understand whether it is true and whether only the certified mailbox or other systems and services of the Interior Ministry were violated and whether other law enforcement agencies are involved. And whether the ministry is aware of similar scams involving other credit institutions”. Consumer associations are also asking for clarity.

The postal police investigation into the scam

Even the postal police and for cyber security is investigating the matter. According to an initial reconstruction, unauthorized individuals would have passed themselves off as representatives of a public authority and, using credentials or addresses attributable to an Italian administration, would have obtained sensitive information on numerous customers from the financial company.

Investigators are trying to reconstruct the ways in which the criminals would have accessed the systems used to make the requests credible and to clarify the actual origin of the communications sent to Revolut.

The UK data regulator, the Information Commissioner’s Office, also said it was investigating the incident after Revolut reported itself to the regulator.

Revolut’s version

The company, a spokesperson told the Financial Times, said it had “immediately blocked the address” after detecting the problem and had informed the regulatory authorities and customers involved. “Revolut systems and customer funds were not compromised,” he added. Since its launch in 2015, Revolut has become Europe’s largest fintech with 80 million customers and a presence in 30 countries. It was recently valued at $115 billion in a secondary stock sale transaction.

Also among the people involved isMark Karpelèsformer CEO of cryptocurrency platform Mt. Gox. Other names, including those of professional athletes, have appeared in the reconstructions circulated online and in the materials attributed to the perpetrators of the attack, but have not yet been independently confirmed.

The association’s complaint

In Italy, consumer associations express concern. The president of Assoutenti, Gabriele Melluso, underlines that “the protection of customers does not only concern the money deposited, but also the personal information that is entrusted to those who offer financial services – declares the president, Gabriele Melluso – The risk is that the data acquired by criminals can be used to construct more credible and targeted fraud attempts. Knowing the name, address or other details of the customer does not make those who contact them authentic. We therefore invite customers to pay maximum attention to phone calls, emails and messages unexpected events. Anyone who impersonates the bank and asks to hand over passwords, PINs or one-time access and authorization codes is attempting a scam. This information must not be disclosed to anyone, even when the interlocutor claims to block a suspicious transaction or protect the account”. Furthermore, he continues, “we ask Revolut for full clarity on the extent of the episode, timely information to the customers involved and concrete assistance to prevent further consequences”.

Codacons also intervenes in the matter: “We want to understand whether among the data delivered to the cyber criminals there is also sensitive information relating to Italian customers, and how many subjects were involved – explains the association – From the news that appeared it would then emerge that other Italian institutions and law enforcement agencies were violated by the criminal group responsible for the Revolut scam. This exposes a multitude of companies to scam attempts through institutional certified e-mailscompletely similar to that suffered by the British company, putting an enormous amount of users’ personal data at serious risk” warns Codacons.

For these reasons, the association asks the competent authorities to take action to ascertain the dimensions of the phenomenon, whether and how many Italian institutions have been violated by cyber criminals and which pecs have been used to steal sensitive data. Codacons is also evaluating possible legal actions to be taken in the event of a violation of the privacy of Italian users.

By Editor