According to people familiar with the situation, after the initial investigation, Revolut contacted 680 people who are believed to have been affected by this scam.
Read more For two operations, border guards detained 6 people for smuggling, 3 of them – officers
Revolut responded urgently throughout the weekend to a data security breach that occurred when a hacker used a genuine government agency email address they had obtained and sent a fraudulent request for private information about several Revolut customers.
Revolut complied with this request and provided confidential information, including addresses, identity verification photos, ID cards, and information about bitcoin transactions.
The hackers, who claim responsibility for this incident, threaten to release the information if Revolut does not pay a ransom.
On Monday, the UK’s data protection authority – the Information Commissioner’s Office (ICO) – announced it is investigating the incident, which Revolut itself reported to the regulator a few days ago.
This incident highlights the growing threat posed by cybercriminals to businesses.
Since its launch in 2015, Revolut has become the largest European financial technology company – it has 80 million customers operating in 30 countries. Recently, in secondary stock trading, the company was valued at 115 billion US dollars.
Read more Expert warns: what data should not be trusted to artificial intelligence
Among the affected customers was Mark Karpelès, former head of Mt Gox, once the world’s largest bitcoin exchange. He said that on September 12 at 5:25 a.m., he received an email from Revolut warning him about the scam and informing him that his data might be at risk.
“At first, I thought it was a scam… At first, I felt sorry for them,” he told the Financial Times.
Karpelès said he now believes that Revolut should not have shared this information at all, regardless of whether the email was sent from a verified government address.
Mt Gox went bankrupt after a large-scale hack, and Karpelès was convicted of electronic data manipulation.
A Revolut spokesperson said the company recently identified “a sophisticated external fraud scheme where an unauthorized third party used a legitimate government agency email domain to submit fraudulent information requests.”
The company said it “immediately blocked the address upon identifying the issue” and informed regulators and affected customers.
Read more This week in Palanga – an opportunity to see live how crosses and roadside shrines are made
Revolut also stated that “its systems and customer funds were not affected.”
The company declined to comment on the exact number of customers affected.