Urgent.News

What's breaking now, across thousands of outlets.

Tech

Lessons must be learnt from cyber attack on Revolut, experts warn

Cybersecurity experts say lessons must be learnt from an incident in which digital banking platform Revolut was deceived into turning over private customer data to hackers . The UK-based financial technology firm with more than 80 million customers confirmed someone posing as an Italian government regulator by email succeeded in procuring identification card information, photos, account…

Lessons must be learnt from cyber attack on Revolut, experts warn

Cybersecurity experts are warning that lessons must be learned from a recent cyber attack on the digital banking platform Revolut, which deceived the company into sharing private customer data with hackers. The UK-based financial technology firm, which has over 80 million customers, confirmed that an attacker posing as an Italian government regulator through email managed to obtain sensitive information including identification card details, photos, account statements, and transaction histories.

Some reports suggest that the hackers are already leaking the stolen data and demanding a ransom to prevent further disclosure.

Technology experts and cybersecurity analysts say that this method of attack could become more common among criminal groups. Ivan Milenkovic, vice president for cyber risk technology at Qualys, explained that while the attackers did not technically breach Revolut's systems, they took advantage of human nature. He highlighted the bank's trust in the email domain of the Italian government as a weak point.

Santiago, a threat-intelligence research lead at Acronis, pointed out that what initially appeared to be a data breach turned into a form of extortion when the hacker demanded around $3 million in a blockchain-based cryptocurrency. Although Revolut claimed not to have received a direct demand, the public countdown created pressure on the bank and affected customers.

Experts emphasize that this type of phishing attack is no longer limited to older or less technically knowledgeable individuals. Art Gilliland, CEO of Delinea, stated that the legitimacy and authority conveyed in the phishing attempt could convince even experienced professionals. He added that the attack likely targeted individuals whose information could provide the most leverage, rather than attempting to collect as much data as possible.

The incident also highlights the importance of verifying sensitive requests through independent channels and implementing appropriate controls. Art Gilliland stressed that no longer can employees, regardless of their technical expertise, be the final line of defense. He emphasized that organizations must verify the legitimacy of emails and restrict access to sensitive information.

Similar incidents on a smaller scale have been reported, with one example involving a social engineering attempt disguised as a podcast. Joan Westenberg detailed an instance where cyber criminals contacted her, requesting her to install a terminal command for a webinar tool. She recognized the attempt and blocked further communication. This highlights the potential dangers of installing custom software or following instructions from unverified sources.

Artificial intelligence has made such attacks easier to execute and scale, according to Milenkovic. While there is no indication that AI was used in this particular case, it has made these tactics cheaper, faster, and more accessible to a wider range of threat actors. Experts warn that this incident serves as a reminder for all organizations to learn from the Revolut attack and implement stricter security measures to prevent similar breaches in the future.

Written by urgent.news from The National Business's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at thenationalnews.com →

More in Tech

More from Monday 21 September →