Lessons must be learnt from cyber attack on Revolut, experts warn
Cybersecurity experts say lessons must be learnt from an incident in which digital banking platform Revolut was deceived into turning over private customer data to hackers . The UK-based financial technology firm with more than 80 million customers confirmed someone posing as an Italian government regulator by email succeeded in procuring identification card information, photos, account…
Cybersecurity experts are warning that lessons must be learned from a recent cyber attack on the digital banking platform Revolut. The UK-based fintech company, which has over 80 million customers, fell victim to an attack where someone posing as an Italian government regulator tricked the company into providing private customer data.
This information included identification card details, photos, account statements, transaction histories, and more. Some reports suggest that hackers are already leaking this data and demanding a ransom to prevent further exposure.
Technology experts and cybersecurity analysts believe that this type of attack could become more common among criminal groups. Ivan Milenkovic, vice president for cyber risk technology at IT security firm Qualys, stated that while criminals did not breach Revolut's systems, they exploited human nature. The weak point, according to Milenkovic, was the desk that handles police requests and the trust placed in government domains.
Santiago, a threat-intelligence research lead at Acronis, noted how the attack escalated from a data breach to extortion, with the hacker reportedly demanding around $3 million in a blockchain-based cryptocurrency. Revolut claimed it had received no direct demand, but the public countdown increased pressure on the bank and affected customers.
Experts argue that such phishing attempts are not limited to older, less technically knowledgeable individuals. Art Gilliland, CEO of Delinea, emphasized that the attack's legitimacy and authority often convince even experienced professionals. He added that the incident highlights the need for independent verification and controls when handling sensitive requests.
Similar social engineering attempts, such as those disguised as podcast interviews, have also been observed. Joan Westenberg, a technology expert, recounted an incident where she was targeted in such a way. She warned against installing custom software or tools for meetings or podcasts, as these can be signs of hacking attempts.
Cybersecurity experts stress that organizations must move beyond technical literacy as the sole line of defense against these types of attacks, emphasizing the importance of verification and appropriate controls.
Written by urgent.news from The National UAE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Lessons must be learnt from cyber attack on Revolut, experts warn thenationalnews.com