The public prosecutor’s office in Reggio Calabria has opened an investigation into a case involving the banking services company Revolut, founded in London, which is now reportedly being blackmailed.

A group of hackers requested sensitive data from the bank using a compromised institutional email account belonging to the Reggio Calabria prefecture.

The digital bank has confirmed that data belonging to around 680 European customers has been affected, but that their funds have not been touched.

According to the Financial Times, which contacted the cybercriminals via Telegram, the group calls itself “iamnotavillain” and posted on its website on Wednesday afternoon a ransom demand for 3 million dollars, equivalent to 2.61 million euros.

If they do not receive the money within 24 hours, the hackers are threatening to sell the sensitive data to other criminal organisations.

The National Anti-Mafia and Counter-Terrorism Directorate is also working on the case, as it concerns a government body. The cybercrime division of the police says it was a highly sophisticated operation, but several points still need to be clarified.
An unusual ransom demand

The group posted the ransom demand on its site on the dark web. The Financial Times (source in Italian) notes that making such a demand public is unusual; typically, ransom and extortion attempts are made privately at first and only made public if the targets refuse to pay.

In this case, however, the British newspaper received a message demanding that Revolut transfer “6,000 XMR / 3,000,000 $… otherwise all the data will be sold and you will have blood on your hands”.

XMR is the ticker symbol for the cryptocurrency Monero, often used in illegal contexts because it is difficult to trace.

The criminal group also told the newspaper that this was the first time it had used its site for a ransom demand and that it had not yet contacted the bank to open negotiations.

After making the ransom demand public, the hackers sent the Financial Times a 60-second screen recording showing an unidentified user scrolling through a collection of documents, possibly belonging to Revolut.

The information contained in the documents taken from Revolut is said to include passport details, driving licence data, other identity documents and photographs. The hackers claim to hold a total of 147 gigabytes of data.
How far the investigation has progressed

Prosecutors are considering the offence of intrusion into an IT system of public interest. An initial report from the cybercrime police indicates that the operation, which lasted for months, was highly sophisticated, and it is still not certain whether a computer at the Reggio Calabria prefecture or at Italy’s Interior Ministry was compromised.

Experts are also trying to establish whether the institutional email account from which the requests originated was infiltrated or cloned.

Alongside the national Anti-Mafia and Counter-Terrorism Prosecutor’s Office, the Italian data protection authority has also stepped in, immediately launching checks for possible security breaches at Italian banks and urging data-protection officers to carry out a “prompt review” and, if any vulnerabilities are found, to notify the authority immediately.

The Italian privacy watchdog has also contacted its counterpart in Lithuania, where Revolut’s registered office is located, starting an exchange of information to strengthen efforts to counter the threat.

The investigation will determine how the offence was carried out and whether other public bodies were also affected.

Via Revolut