The hackers claiming responsibility for Revolut’s recent customer data breach are demanding $3 million in Monero and threatening to sell sensitive information belonging to hundreds of customers if the payment isn’t made. The group, calling itself “iamnotavillain,” publicly demanded 6,000 XMR and reportedly gave Revolut 24 hours to comply. Revolut says it has not received any direct communication or ransom demand from the group.
The attackers published their ultimatum alongside a countdown clock, demanding 6,000 Monero worth approximately $3 million.
The group threatened to sell the stolen information to other criminal organizations if Revolut refused to pay. Monero (XMR) is a privacy-focused cryptocy designed to obscure details including transaction amounts, senders and recipients.
The breach is understood to involve approximately 680 customer accounts, although Revolut has publicly described the affected group only as a limited number of customers.
Information reportedly exposed includes:
Revolut says its core infrastructure, databases and customer accounts were not hacked and customer funds remain unaffected.
The attackers claim the victims weren’t selected randomly.
According to the group, blockchain analysis was used to identify Revolut customers with significant cryptocy holdings before fraudulent requests were submitted seeking information about those specific individuals.
That detail creates an additional security concern because leaked identity documents, transaction histories and home addresses could potentially connect high-value onchain activity with real-world identities.
The attackers didn’t reportedly break directly into Revolut’s banking infrastructure.
Instead, Revolut previously confirmed that an unauthorized party used an email address associated with a legitimate government agency domain to submit fraudulent information requests. Revolut responded to the requests before discovering they were fraudulent.
The attackers separately claim they compromised an Italian government email system and posed as law enforcement over several months. That account has been reported by the Financial Times but hasn’t been independently confirmed by Revolut.
After discovering the scheme, Revolut says it blocked the address and contacted the relevant government agency, law enforcement and regulators.
Despite the public ultimatum, Revolut told Reuters that it hadn’t received direct contact or a ransom demand from the individuals claiming responsibility as of September 16.
That means the $3 million demand currently represents a public threat from the alleged attackers rather than an acknowledged private negotiation between Revolut and the group.
What began as a fraudulent government-data request has now escalated into an alleged multimillion-dollar extortion attempt.
The combination of KYC documents, physical addresses and crypto transaction histories is particularly concerning for cryptocy holders because blockchain activity that was previously pseudonymous could potentially be connected with specific individuals.
With the attackers now demanding 6,000 XMR and threatening to sell the information, the Revolut incident has evolved from a serious privacy breach into a broader security threat for the customers whose identities and crypto activity were exposed.
Less than 24 hours after the CLARITY Act failed to clear its Senate procedural hurdle,…
Circle has officially launched the public mainnet of Arc, its new Layer 1 blockchain built…
U.S. lawmakers have advanced legislation that would turn President Donald Trump’s Strategic Bitcoin Reserve from…
Pixelmon is officially ending game development and laying off its gaming team after an external…
The CLARITY Act suffered a major setback in the U.S. Senate after lawmakers failed to…
A Zcash user says approximately $589,000 in USDT has remained inaccessible through NEAR Intents for…