Threat Intelligence Brief
Curated summary with source attribution
Source: amlintelligence.com
Threat Risk: High
Victim: Financial institutions and fintech companies
Incident: A data breach at Revolut involving fraudulent law enforcement data requests.
Impact: Exposure of sensitive customer bank statements and postal addresses, increasing risks of financial crime and physical danger.
Attacker: Unidentified threat actors using compromised law enforcement credentials
Analysis: Threat actors are compromising law enforcement email accounts to send fraudulent emergency data requests to corporations. By exploiting the pressure to comply with time-sensitive, life-and-death situations, attackers bypass standard verification processes. This technique facilitates the theft of highly sensitive PII, including bank statements and residential addresses.
Recommendations: Implement strict multi-channel verification for all emergency data requests.; Require cryptographic signatures or verified government portals for official communications.; Train compliance and legal teams to identify the indicators of fraudulent official requests.
Source: AML Intelligence
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source