Researchers have uncovered a scheme involving fake 'crypto requests' sent to fintech firm Revolut. Attackers used compromised email accounts belonging to Italian government agencies to send fraudulent inquiries to the company. This led to a data leak impacting roughly 680 Revolut customers.

How the Attackers Pulled It Off

The key to the attack was using hacked official email addresses from Italian government entities. Messages coming from these addresses looked legit, mimicking real requests, which made it easier for Revolut to process them as genuine. The emails were framed as 'crypto requests,' which boosted the level of trust in their content and intent.

Scale and Fallout of the Incident

About 680 Revolut customers had their data exposed as a result of this attack. Reports highlight the consequences for the company after it handled fake requests sent from compromised government email inboxes. There aren’t any more details yet about exactly what kind of data was leaked or how much was involved.