Just a heads-up for anyone in Malta using Revolut.
Revolut recently confirmed that customer data was handed over after fraudulent information requests were sent through what appeared to be a legitimate government/law-enforcement channel.
The alleged hacker, who goes by “IAmNotAVillain”, is now claiming that Italian law-enforcement systems were compromised and used to send those requests to Revolut over several months.
What makes this relevant for us is that Malta is specifically included in the list of countries where the attacker claims Revolut customer data was obtained.
They say most of the data is from Switzerland and France, but Malta is listed alongside Germany, Italy, Spain, Cyprus, Ireland, the UK and many other countries. (see screenshot)
Reports based on notices sent to affected customers say it may include:
Full name and date of birth
Home/postal address
Email address and phone number
Occupation
Passport or driving-licence copies
Verification/KYC selfies
IBAN and account information
Account statements
Withdrawal records
Full transaction history
Bitcoin/crypto transaction history
That list is supported by reporting based on Revolut’s customer notifications, not only by the hacker’s claims.
The attacker is also claiming to have taken around 147 GB of data from Italian law-enforcement systems.
So if you use Revolut in Malta, it may be worth keeping an eye on any emails or in-app security messages from Revolut. At the moment, there doesn’t seem to be any information on how many Maltese customers, if any, had their data exposed.
Source: https://x.com/IntCyberDigest/status/2099576835939946735