/
    Zpět na blog
    Security Sunday

    Your money is safe. You might not be.


    Your money is safe. You might not be.

    image

    Today, I have two stories from the financial world for you. The first concerns the Czech group Partners; attackers gained access to its data in late August, and this week, the INC Ransom group provided an update claiming the scope of the attack is significantly larger, estimating the total volume of data at 1.5 to 2.5 TB. The second story involves Revolut, which handed over data to an attacker acting on an order from a compromised government institution.

    Revolut and Partners

    Today I have two stories from the world of finance.

    The first is the Czech group Partners, where attackers got hold of its data at the end of August.

    The second is Revolut, which handed data over to an attacker.

    In both cases the companies say the same thing: client money was untouched — and by all appearances that holds.

    Partners

    Let’s start with the Partners story.

    On Thursday 27 August, Petr Borkovec, co-founder and head of the financial group Partners, wrote on LinkedIn that the group had faced a cyberattack. The company also sent a statement to the media and gradually began notifying clients. The attack itself is said to have happened the Sunday before.

    The affected entities are the advisory arm Partners Financial Services, the insurer Simplea, the pension company Rentea, Partners investiční společnost, and in Slovakia the advisory firm Simplea Financial Services. According to the group, Partners Banka and its systems were not affected.

    Borkovec described what happened fairly openly. In his account, the attackers’ goal was to encrypt everything, steal it and then extort. They didn’t manage that: they never reached the production environment and operations were not interrupted. They did, however, reach the backups and non-production environments — and through them, clients’ personal data.

    According to the information sent to clients, this mainly concerns identification and contact details, contract data, and call-centre recordings up to 2021. For clients of the insurance, pension and investment companies the scope may be wider; investment questionnaires and insurance-claim reports are mentioned.

    The company says the data was encrypted. At the same time it says itself that you have to assume the attackers have the tools to decrypt it. I appreciate that Partners communicates this openly. It’s more honest than hiding behind “it’s encrypted”.

    The whole group has roughly 600,000 customers. How many of them the breach affects, the company hasn’t specified. Nor is it publicly known who is behind the attack — at least not from a confirmed source. The company has not named the attacker and has not published the results of its forensic analysis.

    What INC Ransom claims

    A few days ago, however, new information surfaced. On the leak site of the ransomware group INC Ransom there is a post titled Partners Financial Services, a. s., with the company’s Prague address and company ID number. The post is dated 11 September, and the open tracker RansomLook, which monitors these groups’ sites, picked it up on 16 September.

    A word of caution here. Everything you’re about to read is a claim made by the attackers on their own site, and attackers have every reason to exaggerate, because that’s how they pressure the victim. As of today Partners has not publicly confirmed it, and I have neither seen nor downloaded any stolen data. I’m going purely by the ransomware group’s post.

    According to the post, they have the complete Active Directory of the entire group — ten domains, roughly 1,850 user accounts, 156 of them privileged — plus the material needed to forge a so-called golden ticket, which is effectively a ticket to owning the whole corporate network.

    They further list over 1.3 million call-centre recordings from 2008 to 2021, backups of the client SQL database from this August, and Veeam backup infrastructure with images of fifteen production servers. They estimate the total volume at 1.5 to 2.5 TB of data.

    Some of that matches what Partners said itself: call recordings ending in 2021, and the fact that the route ran through backups. On one point, though, the two versions diverge. Partners talks about backups and non-production environments. The attackers claim they have the entire Active Directory — and if that were true, you automatically burn the whole forest and rebuild the corporate infrastructure from scratch.

    The post also includes a sample of allegedly cracked passwords. I won’t show them, because they come with the names of specific employees. I’ll only say that if they’re real, they’re the keyboard-row or month-and-year kind of password.

    The post also includes a countdown. When the screenshot was taken, it showed just under nine days until the access credentials to the data store would be published. If the screenshot was taken on 16 September, that works out to 25 September.

    With groups of this type, a victim usually shows up on the leak site when they haven’t paid or when negotiations are going nowhere. Whether that’s what happened here I don’t know, and I don’t want to speculate.

    INC Ransom is a ransomware-as-a-service group active since July 2023 that works by double extortion: encrypt the data, steal it, and threaten to publish it.

    RansomLook lists over 900 published victims for the group, with 37 added in the last thirty days. According to security firms, it gets into networks mainly through vulnerabilities in internet-facing services, through phishing, and through valid VPN or RDP credentials. That’s a generic vector, though, and says nothing about how the attack on Partners actually happened.

    For clients, one thing changes here. Until now this was data held by a single group. If the attackers publish or sell it, other fraudsters will get their hands on it.

    If the data really does include call recordings, they contain the client’s voice together with what they were calling about — which opens up the fake-adviser or fake-banker vector. That’s just my own reasoning, though, not a confirmed fact.

    Revolut

    The second story comes from Revolut.

    On Saturday 12 September, Revolut confirmed to TechCrunch and Reuters that it had handed sensitive data on some of its clients to an unauthorised third party.

    Nobody broke into its app or its databases. The attacker sent an information request that looked like a routine request from a government authority. It came from the authority’s legitimate domain, and Revolut responded the way it responds to such requests. It sent the data.

    Revolut itself calls this a sophisticated impersonation scam and stresses that neither its systems nor client money were affected.

    What exactly went out to the attackers we know from the notice Revolut sent to the affected individuals: date of birth, postal and email address, phone number, and copies of identity documents including passports and driving licences. For some clients possibly also verification selfies, account statements and transaction history. People who published their notices add IBAN, withdrawal records and bitcoin transaction history.

    The first notices started reaching clients on Friday 11 September. Over the weekend an account appeared on Telegram claiming responsibility, began publishing data samples, and demanded 10,000 bitcoin from Revolut.

    The Record writes that the screenshots pointed to an Italian domain, that the account was subsequently blocked, and that not everything in those posts could be verified. Revolut declined to comment on whether any negotiation is taking place at all.

    Italy uses the PEC system — certified electronic mail. It’s roughly the equivalent of the Czech data box. If the attackers really did control a prefecture’s mailbox, then their message passed every technical check — the compliance team saw a message from a genuine official mailbox and had no reason to distrust it.

    And how did they get into that mailbox? The attackers claim the campaign ran for five to six months and that they obtained access to civil servants’ accounts via infostealer malware. Take that as the attacker’s claim; the Italian authorities have not confirmed it.

    Early this week the Financial Times came out with a figure: 680. That’s how many clients Revolut was said to have contacted.

    Interesting for us is the statement Revolut sent to the Czech outlet Lupa. In it, the company denies that the incident involved biometric data or login credentials. It did not, however, give a specific answer to the question of whether Czech clients are among those affected.

    Mid-week the investigation moved to Italy. According to the ANSA news agency, the attackers abused the certified email address of the prefecture in Reggio di Calabria.

    On Wednesday 16 September the attackers changed their demand. No longer 10,000 bitcoin, but 6,000 monero — roughly three million dollars — plus a public 24-hour countdown and a threat to sell the data to other groups. Revolut says it has received no ransom demand.

    When an attacker holds your passport, your photo, your address and your phone number, together with an overview of how much crypto you’ve bought and where you sent it, they have a ready-made profile of someone worth a try. The phone number can be targeted with SIM swapping. The email with phishing that quotes your real transactions. For people who visibly hold a lot of crypto, extortion is on the table too, because the attacker knows your address.

    Another notable point: The Record explicitly writes that it isn’t known whether the same domain also approached other financial institutions. If I were sitting in the compliance department of any bank or crypto exchange today, including Czech ones, I’d go back through the messages from Italian authorities.

    The countdown expired on Thursday 17 September with no public reaction. It isn’t known whether Revolut paid, or whether the attackers sold the data as they threatened.

    What this means for you as a client

    If you’re a client of any of the affected companies, expect that someone may contact you who knows surprisingly much about you. If a copy of your ID document was leaked, consider replacing it.

    Let me know in the comments whether you, as a Revolut or Partners client, received any notification and what it said.

    © 2026 Patrik Žák. Všechna práva vyhrazena.