
Criminals gained access to the data of thousands of Revolut customers using false requests based on the Italian PEC system and the official mailbox.
AI-generated summary
Revolut previously fell victim to a security incident four years ago, when the data of over 50,000 users was leaked in a phishing attack.
What data was leaked?
According to the notifications sent by Revolut to the victims, the criminals gained access to virtually all data the company had about its customers. The stolen information included:
- name and surname,
- date of birth,
- profession,
- residential address,
- e-mail,
- telephone number,
- scans of identity documents (passport, driving license),
- selfie from the KYC verification process,
- account statements, IBAN numbers,
- full transaction history, including Bitcoin transactions.
This is a real mine of knowledge for cybercriminals, who can now carry out targeted attacks on specific people and also use data for identity theft.
Who was harmed?
Revolut did not disclose the exact number of victims, only stating that it was a "very limited" group of customers.
Up to 680 people may be injured, mainly wealthy clients and people associated with cryptocurrencies. According to information provided by one of the attackers, the victims include people from over 30 countries, including Poland, Germany, Spain, Italy and Great Britain.
How did the leak occur?
The attack scenario was presented by the website niebezpiecznik.pl. As it turns out, the criminals took over access to the e-mail box belonging to the Italian PEC system, which is used for official correspondence. Then, using false requests based on the European Investigation Order, they sent requests to Revolut to disclose customer data. For five months, the company passed on the information without realizing that the demands were false.
According to Italian media, the criminals used malware to take control of the official mailbox and effectively concealed their activities from the real owner of the account.
Errors on Revolut's website?
Although the attack was advanced, experts leave no stone unturned on Revolut. They point out that the company should have verified the authenticity of the demands, especially since they lacked the required court orders. Instead, Revolut passed on the data thoughtlessly, trusting the authority of the official email inbox.
Blackmail and publication of data
Cybercriminals did not stop at extorting data. Some of them have already been published online, and criminals are threatening to reveal further records until Revolut pays the ransom.
The disclosed data included information about famous people, including: athletes and company presidents.
This isn't the first time
This is not the first time Revolut has lost customer data. Four years ago, the company fell victim to phishing, which leaked the data of over 50,000 users. This time, however, there was no classic "hacking" of the systems - it was enough to exploit loopholes in the request verification procedures.
Experts emphasize that each of us should be careful when providing our data to companies and institutions. It is worth regularly monitoring information about leaks and using online safety tips.

Scientists have found that the presence of lead in ancient inks makes it easier to read charred scrolls from Herculaneum using X-ray tomography and artificial intelligence, opening the way to discovering unknown ancient texts.

OpenAI revealed six cases of disturbing behavior by AI models, including an attempt by a research model to bypass restrictions. The company calls for slowing down the development of technology due to the risk to humanity.

The European Commission will present a draft regulation "EU Kids Act", which assumes a ban on the use of social media for children under 13 years of age and a limited account under parental supervision until the age of 15. Poland supports the initiative, but wants to retain the possibility of setting a higher age limit at national level.

Dr. Leszek Bukowski in an interview with Radio RMF24 discusses the threats related to AI. The expert points to the rivalry between the US and China, the business strategies of technology companies and the risk of losing control over self-reinforcing artificial intelligence models.

After the data leak of 19 million Poles from the MyDr system, the Office of Personal Data Protection initiated an inspection of the software supplier. The office also announced extensive audits in the health care sector to verify the security of medical data processing.

Children under 13 will lose access to social media. For teenagers, mini-accounts under parental supervision and more secure versions of the platforms have been introduced.