Revolut, customer data sent to hackers via certified email: how the scam occurred and how to defend yourself

Revolut, customer data sent to hackers via certified email: how the scam occurred and how to defend yourself

Almost seven hundred account holders exposed without anyone having forced a lock. This is what happened to the British giant Revolutwhich started as a young digital payments company and grew to undermine the continent’s large credit institutions. Passports, home addresses, account details and transaction history have ended up in the hands of a group of cyber criminals. The bottom line is that Revolut did not suffer an intrusion into its servers.

In fact, according to what the authors of the robbery themselves said, the lock pick would have been a certified email address belonging to the Italian police force, compromised at a previous time and then reused as a pass. From that address a formal request for data delivery was made, motivated by the urgency of an investigation (which in reality did not exist), a request which passed the authentication checks and initially did not arouse suspicion. Subsequently, the exchange of emails continued until the company contacted the Italian institution directly, which denied ever having sent those messages.

What happened to Revolut

The company, the largest European fintech group, with over 80 million users, of which approximately 5 million are Italian, issued a statement in which it explained that it had “identified a sophisticated external impersonation scam, in which an unauthorized third party used an email with a legitimate domain of a government agency to send fraudulent requests for information. Upon detection we immediately blocked the address and notified the relevant government agency, law enforcement, data protection authorities data and financial regulators. Revolut systems and customer funds were not affected.”

For the company, the people involved would be very limited in number, with the Financial Times speaking of around 680 customers contacteda figure that Revolut did not want to confirm. The Italian Postal Police are now working on the episode, for abusive access and computer fraud, and the British Information Commissioner’s Office, which opened an investigation on 15 September after the company’s spontaneous report.

How the scam was built

The data breach would have been claimed by the hacker group IAmNotAVillain and to understand how the deception managed to seem credible we need to start from when it all began, six months ago. The cyber criminals said that it all started from the violation of a PEC mailbox of the Ministry of the Interiordocumented with screenshots of message headers. 147 gigabytes of documents, diaries and personal data would have been stolen from there. That address was then used to send a request for customer information to Revolut’s Lithuanian headquarters, motivated by an investigation attributed to the Milan prosecutor’s office.

The front door would have been an infostealera malware designed to collect and exfiltrate sensitive information from compromised devices. The hacker then took possession of the credentials to access the email account of a government employee and then created a fake European Investigation Order with which to demand Revolut hand over the information. The technique falls into the category of Man in the Maila mechanism through which a criminal inserts himself into an already active mailbox and, from that location, carries on correspondence by pretending to be the legitimate owner.

How to defend yourself

In the space of a few years, infostealers have become a leading weapon in the cybercrime arsenal. The National Cybersecurity Agency, in its report, identifies some concrete countermeasures to strengthen defenses against a threat that is constantly changing.

A first precaution is themulti-factor authentication (MFA), to be activated on each account. The rule then applies do not open links or attachments contained in unexpected or out of the ordinary messagesin case of doubt, the right way is to check the validity of the communication on the organisation’s official channels or contact its institutional contact details directly. Systems and devices must always be kept aligned with the latest available versions, installing patches and security updates as soon as they are released.

It is also advisable disable automatic saving of passwords in browsersinstead relying on a dedicated manager, with an encrypted database and created by a proven manufacturer. It remains essential for companies to regularly organize training and raise awareness of staff on IT risks and the good practices to be adopted.

In the coming weeks it is prudent to look with suspicion at any unexpected contact, each message must be verified by accessing the official app or calling the numbers published on institutional channels, never those indicated in the communication received. It is also a good idea to carefully monitor your account movements, activate two-factor authentication on all financial services and replace passwords that are reused across multiple platforms.