The available evidence points to a targeted attack, rather than the random collection of customer files. Recorded Future News / The Record reports that the attackers focused on wealthy individuals, many of them involved in the crypto industry. Among the victims who have publicly disclosed their cases are Mark Karpelès, the former CEO of the Mt. Gox exchange, and Marc Zeller, a crypto entrepreneur and one of the better-known figures in the Aave ecosystem. Revolut has not disclosed the criteria used to select the 680 individuals, but the combination of the extremely limited number of victims, the profile of those already identified and the available information about the operation makes the possibility of a random selection highly unlikely.
The incident has meanwhile entered a second phase: extortion. The Financial Times reports that the attackers are threatening to publish the information they obtained unless Revolut pays a ransom. Separately, Computing reports that the demand may amount to 10,000 BTC, valued at approximately $782 million at the time of publication. Revolut has not publicly confirmed that figure, which should therefore be treated as a claim attributed to the attackers rather than an independently established fact.
For now, the extortion appears to be directed at Revolut itself. It remains unknown whether the individuals whose files were obtained are, or may separately become, targets of blackmail, fraud, social engineering or other forms of pressure. The distinction is particularly important for crypto holders: linking a real identity and physical address to transaction history can allow an attacker to estimate an individual’s financial profile far more accurately than blockchain analysis alone. Reported potentially exposed information includes identity documents, verification selfies, IBANs, account statements and transaction histories, including Bitcoin activity. These categories of data have been described in reports based on notifications sent by Revolut to affected customers. The Record
There is also a first geographical clue regarding the public institution from which the compromise originated. The Record reports that images circulated by the attackers on Telegram as part of their extortion campaign suggest that the email originated from an Italian domain. The publication contacted several Italian authorities but received no response. There is therefore now a significant indication pointing to Italy, but still no factual basis for attributing the breach to any specific Italian institution.
Comments
Comments are moderated before publication.
No approved comments yet.