If you remember this post, then the follow up will be of interest to you. Revolut’s hackers claim that they were able to access sensitive data about wealthy customers by using a compromised Italian government email system to impersonate Italian law enforcement. This wasn’t a break in, Revolut handed over the keys.
Jeremy Leasher, Forward Deployed Security Architect, Binalyze said this
“The hackers claim to have breached Revolut using inherent authority – in this case an Italian government’s email system to simply ask for the data they wanted.
“The biggest concern this raises is how long the hackers claim to have been inside the Italian government’s e-mail system. Supposedly communicating with Revolut over several months to build up a treasure trove of ransom-able information. That doesn’t happen without evidence: there will have been logins, emails and files being sent and received, that should have set alarms ringing – but clearly didn’t. A key takeaway to remember is that we almost certainly don’t yet have the full picture of what the hackers got up to whilst they were in the system. There will be artifacts that prove what data was touched by the threat actor, and when. Having that visibility earlier could have meant earlier detection: and that’s what organisations should strive for.
“The Italian authorities should be taking immediate action to investigate at a deep level how the attackers gained access and what else they were able to do whilst they were inside their systems. Organisations both private and public need to be continuously alert for this kind of unauthorised activity, highlighting anomalies so they can be investigated before they turn into a crisis.
“For those that have fallen victim to this breach and had their data disclosed it would be wise to ensure they are following the personal cybersecurity basics to keep themselves as safe as possible. This should include:
- Enable strong multi-factor authentication (MFA) wherever possible: It’s easy to assume that all forms of MFA are equal. But passkeys or hardware-based methods that take more technical acumen, are much more secure and give more peace of mind than text messages.
- Use a password manager: The most secure approach to passwords is to have a different one for every account. But most people’s memory can’t manage this; either passwords will be too simple, repetition will creep in. A password manager creates unique passwords for every account while offloading the memory work.
- Regularly review account activity. Perhaps the most simple action, but there should be no place for unknown devices or sessions on your key accounts. A regular check on which devices are authorised and logged in will pay dividends in reporting and removing anything suspicious.”
This is a massive amount of pwnage. And deserves an investigation to match. Otherwise we are all wasting our time.
Related
This entry was posted on September 16, 2026 at 3:55 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Hackers sitting undetected for months is the real Revolut breach story
If you remember this post, then the follow up will be of interest to you. Revolut’s hackers claim that they were able to access sensitive data about wealthy customers by using a compromised Italian government email system to impersonate Italian law enforcement. This wasn’t a break in, Revolut handed over the keys.
Jeremy Leasher, Forward Deployed Security Architect, Binalyze said this
“The hackers claim to have breached Revolut using inherent authority – in this case an Italian government’s email system to simply ask for the data they wanted.
“The biggest concern this raises is how long the hackers claim to have been inside the Italian government’s e-mail system. Supposedly communicating with Revolut over several months to build up a treasure trove of ransom-able information. That doesn’t happen without evidence: there will have been logins, emails and files being sent and received, that should have set alarms ringing – but clearly didn’t. A key takeaway to remember is that we almost certainly don’t yet have the full picture of what the hackers got up to whilst they were in the system. There will be artifacts that prove what data was touched by the threat actor, and when. Having that visibility earlier could have meant earlier detection: and that’s what organisations should strive for.
“The Italian authorities should be taking immediate action to investigate at a deep level how the attackers gained access and what else they were able to do whilst they were inside their systems. Organisations both private and public need to be continuously alert for this kind of unauthorised activity, highlighting anomalies so they can be investigated before they turn into a crisis.
“For those that have fallen victim to this breach and had their data disclosed it would be wise to ensure they are following the personal cybersecurity basics to keep themselves as safe as possible. This should include:
This is a massive amount of pwnage. And deserves an investigation to match. Otherwise we are all wasting our time.
Share this:
Like this:
Related
This entry was posted on September 16, 2026 at 3:55 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.