Computer failure, hacking, kidnapping… Revolut denies that the incident suffered this week fits any of those definitions and describes what happened as a “sophisticated case of identity theft” that has raised alarms among users and the financial sector due to the vulnerability they are exposed to by the advancement of digitalization and the development of artificial intelligence.
Read more El Trompas confesses to the Mexican authorities that he killed the Spanish student Claudia Tacoronte
The neobank confirms the impact on 680 clients worldwide, as Financial Times reported, and also assures that no one has asked them for a ransom of three million dollars to recover the stolen information. “Revolut has not had direct contact nor received any demands from those claiming responsibility for this breach,” the British-origin neobank tells this newspaper.
In its version, the company explains that an unauthorized third party used the legitimate email domain of a government agency to fraudulently request information. “As soon as we became aware of the incident, we immediately blocked the involved email address and notified both the government agency and the competent authorities, data protection regulators, and the corresponding financial regulators,” a spokesperson explains. Regarding the effects, the bank states that neither the systems nor the clients’ funds have been affected. “We have already contacted directly the small number of affected people to inform them of what happened and offer them all our support,” they add.
The identity of the government agency has not been disclosed, but it was key in the process carried out by the attackers. Financial institutions are legally required to comply with official requests from public bodies or law enforcement agencies. This means that any communication coming from a verified official domain is handled as a legally binding requirement. Since the requests had valid domain technical authentication, they were processed following the usual compliance procedure (compliance), under the reasonable presumption that it was a legitimate request from an official entity.
After the incident, the bank also notified the impersonated government agency as well as the competent authorities, data protection regulators, and the corresponding financial regulators about what happened.
Read more Cuca Gamarra accuses the Government of Spain of wanting to «turn Ceuta into a permanent CETI»