EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Revolut遭黑客攻击,数据泄露后勒索300万Monero

2026-09-17 06:40:03
Bookmark

Revolut数据泄露事件:黑客索要6000枚门罗币,威胁24小时内付款否则公开数据

针对Revolut客户数据泄露事件的幕后黑手已提出勒索要求,金额高达6,000枚门罗币(Monero),价值约300万美元。黑客威胁称,若银行未在24小时内支付赎金,他们将出售窃取的记录。

事件概要

  • 黑客向Revolut索要6,000枚XMR,估值约为300万美元。
  • 在欺诈性的政府请求通过公司审核后,至少有680个客户账户受到影响。
  • 据报,被盗记录包括身份证明文件、验证照片以及完整的交易历史。
  • 攻击者表示,区块链分析帮助他们识别出持有大量加密货币的客户。

黑客设定24小时最后期限

据《金融时报》报道,一个自称“iamnotavillain”的组织于周三发布了勒索要求,并附带了一个倒计时时钟。黑客声称,如果Revolut不在24小时内发送6,000枚XMR,他们就会将这些客户记录提供给其他犯罪集团。

按每枚代币约500美元的隐含价值计算,总需求约为300万美元。该组织选择门罗币是因为这种加密货币旨在隐藏有关发送方、接收方和涉及金额的_transaction_信息。

According to the Financial Times, at the time of the report's release, no negotiations had taken place between Revolut and the hackers. Revolut did not say whether it planned to respond to the request, nor did it confirm whether the group controlled the stolen information.

The hacker provided the media with a 60-second screen video that appeared to show some of the materials he held. The video reportedly showed passports, driver's license, customer photos submitted during a "Know Your Customer"(KYC) check and customer transaction history.

Although at least 680 accounts were affected, Revolut only publicly described the number of people affected as a "very limited" part of its customer base. Previous reports pointed out that the UK's Information Commissioner's Office (ICO) had launched an investigation after the company reported the incident to regulators.

Revolut said its own systems and client funds were not compromised. Instead, the disclosure occurred because the company received a fraudulent request from an email account using the domain name of a legitimate government agency.

Faked government request exposes Revolut's customer records

The attacker did not directly hack into Revolut's infrastructure, but instead pretended to be a government official seeking customer information. These requests carry valid domain name authentication credentials and pass the checks used by Revolut to assess their authenticity. Revolut had provided customer records before discovering that the request was fraudulent. Once the scam was discovered, the company said it had blocked the email address and contacted relevant government agencies, law enforcement agencies, data protection agencies and financial regulators.

As previously reported, the leaked information included full name, date of birth, occupation, home address, email address and phone number. Copies of passports or driver's license and selfies provided for identity verification are also included in the records listed.

Account data includes International Bank Account Numbers (IBAN), account opening dates, account status, withdrawal records and complete transaction history. Bitcoin wallet reference numbers and Bitcoin transaction records are also included in certain account statements.

Revolut's customer notification distinguished between identity check photos and biometric facial telemetry data, which the company said was not within the scope of disclosure. The notice also stated that the leaked information did not contain private keys, passwords, security codes or complete bank card details.

An earlier statement from the company described the incident as a "complex disguised external fraud" and insisted Revolut's systems remained secure. The company has not publicly confirmed which government agency's email domain name is used, nor has it explained how attackers gained access to accounts running through the domain name.

Blockchain analysis has reportedly targeted crypto-asset-rich targets

Hackers told the Financial Times that they used blockchain analysis to select Revolut customers who appeared to hold large amounts of cryptocurrency. If accurate, their accounts suggest that the affected groups were selected in part through their financial activities rather than the random collection of customer profiles.

链上调查员ZachXBT此前曾表示,该事件似乎涉及高净值用户,尽管Revolut尚未证实这一评估。黑客的最新声明提供了类似的 targeting 方法描述,但尚未得到独立验证。

公共区块链可以暴露交易历史、钱包余额以及地址之间的转账。当交易所、金融公司或其他服务提供商持有将客户账户与区块链地址联系起来的记录时,分析师有时可以将这些活动与已确定的人联系起来。

泄露的Revolut记录可能包含这种联系的双方。身份证明文件和联系信息可以识别账户持有人,而比特币交易历史和钱包参考号可以映射个人加密活动的一部分。

一份关于隐私硬币的八月综述解释了门罗币使交易隐私成为强制性的。其环签名模糊了真实发送者,隐身地址隐藏了接收者的公共地址,而环 confidential transactions (RingCT) 则隐藏了发送的金额。

门罗币的被滥用并不意味着该代币或其所有用户都从事非法活动。门罗币也为寻求财务隐私的人服务,但其设计使得非法支付轨迹比在比特币或以太坊等透明网络上进行的活动的调查更为困难。

另一起八月的案例显示了同样的挑战,调查人员表示,据报道来自790万美元Coinsbuy黑客攻击的资金已被转换为门罗币。区块链公司在一些资产据报道兑换为XMR之前,通过多个交易所追踪了部分资金。

此次泄露对美国加密客户意味着什么

《金融时报》的报告未具体说明这680个受影响的账户中是否有美国客户。然而,经过验证的身份记录和加密交易数据的结合,对于收到声称来自Revolut、交易所、政府机构或钱包提供商消息的美国公民来说,构成了相关的风险。

此类记录允许犯罪分子制作包含真实姓名、交易、账户细节或身份证明文件的消息。准确个人信息的存在并不能证明来电者或发送者代表银行。

Revolut的美国安全指南表示,公司不会突然致电客户并要求其付款或披露验证和安全代码。收到可疑联系的 customers 可以通过公司应用程序内的支持渠道进行验证。

对于个人 Banking 信息曝光的美国公民,联邦贸易委员会(FTC)指导消费者前往 IdentityTheft.gov 获取基于所涉数据类型的步骤。该机构还建议用户通过 ReportFraud.ftc.gov 报告网络钓鱼尝试。

FBI互联网犯罪投诉中心(IC3)要求报告与加密货币相关的欺诈行为的人们,在可用时提供钱包地址、交易金额、资产类型、交易哈希值以及转账的日期和时间。

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP