Revolut Hackers Demand $3 Million in Monero as Breach Exposes Crypto Holders' Data
Key Takeaways
- •A group calling itself 'iamnotavillain' demanded $3 million in Monero and threatened to sell the stolen records, according to the Financial Times, while Reuters reported Revolut had received no ransom demand or direct contact.
- •The breach occurred when attackers impersonated a government agency via email to submit a fraudulent emergency data request, and Revolut stated that its core systems and client funds were not compromised.
- •Roughly 680 customer files were reportedly exposed, including names, addresses, ID documents, verification selfies, bank statements, and transaction lists, with analysts suggesting high-net-worth crypto holders were deliberately targeted.
- •Exposed KYC data can connect visible on-chain wealth to real-world identities, heightening physical-security concerns amid reported increases in violent attacks against cryptocurrency holders.
- •The incident is likely to pressure centralized platforms to independently verify official data requests and tighten compliance, and it comes as Revolut awaits final U.S. approval to form a national bank.

Hackers who tricked Revolut into handing over customer data are demanding a $3 million ransom in exchange for keeping the information confidential, according to a by the Financial Times. The stolen records include identity documents, home addresses, and transaction histories tied to accounts heavily exposed to cryptocurrency.
The ransom demand is only part of the problem. The stolen data could connect visible on-chain wealth to real-world identities. For Revolut, which recently received conditional approval from the U.S. Office of the Comptroller of the Currency to form a national bank — a preliminary stage that precedes any final approval — the incident raises a larger question: how does the centralized financial system protect its KYC data?
A Monero ransom and a threat to leak
According to the Financial Times report, a group calling itself “iamnotavillain” demanded $3 million in Monero and threatened to sell the records if Revolut did not comply. Reuters, however, said Revolut had received no ransom demand or direct contact from the attackers. One source cited by the outlet said around 680 customer files had been compromised, although Revolut has offered no specifics, referring to the number of affected customers only as “limited.”
Monero is a privacy-focused cryptocurrency whose blockchain is designed to conceal sender, recipient, and transaction amounts — unlike transparent public ledgers such as Bitcoin’s, which anyone can examine.
In a separate report, the Financial Times said the attackers also claimed to have hacked an email system of the Italian government and carried out blockchain-focused analysis to identify Revolut customers who hold large amounts of cryptocurrency. Revolut has not confirmed that claim on its own.
How the records left Revolut
According to Revolut, its core systems and client funds were not compromised. Instead, an email account from the domain of a legitimate government agency was used to submit fraudulent information requests. Emergency data requests are designed to let law enforcement obtain user records quickly in urgent situations, without the formal legal process that routine requests typically involve. The company described the incident as a “sophisticated external impersonation scam” and said it blocked the email address as soon as it became aware of the scheme.
The leaked information included names, dates of birth, home addresses, phone numbers, ID documents, verification selfies, bank statements, and transaction lists. The Block reported that former Mt. Gox executive Mark Karpelès said he was affected by the breach and shared a notification from Revolut stating that details about his Bitcoin transactions had been revealed.
“Revolut customers were targeted in a fraudulent emergency data request sent via an email at a ‘government agency.’” — Mark Karpelès (X post)
According to on-chain analyst ZachXBT, the attack appeared deliberate rather than random.
“While the incident is likely limited in size it seems to have been targeted at high net worth users.” — ZachXBT
Why exposed KYC becomes a safety problem
The exposed records stem from Know Your Customer (KYC) checks, the identity-verification requirements that lead regulated financial firms to collect and hold sensitive records such as ID documents, verification selfies, and bank statements. A leaked home address paired with evidence of large crypto holdings can therefore turn a data breach into a physical-security threat. Chainalysis says many violent crypto attacks are premeditated, with victims identified through leaked data, social media, blockchain analysis, or insider information. The firm adds that its figures likely undercount real losses because many attacks go unreported.
CertiK likewise describes its dataset as indicative rather than exhaustive. According to its findings, France accounted for 33 of CertiK’s 52 verified H1 cases, while home invasions jumped from one in H1 2025 to 20. Cryptopolitan previously reported on that sharp rise in physical attacks.
Pressure lands on centralized platforms
The broader market impact is more likely to show up first in security and compliance spending than in crypto prices. Platforms holding KYC records face greater pressure to independently verify official data requests and to limit how much sensitive information a compromised process can expose. The European Banking Authority already ranks cyber risk and data security as the leading operational-risk driver for banks, followed by fraud.
That matters because users remain heavily concentrated on centralized venues. Research by the UK’s Financial Conduct Authority found that 73% of UK crypto users obtain assets through centralized exchanges, while 25% said tighter regulation would make them more likely to invest. Revolut, with more than 80 million customers, sits squarely at intersection of banking, crypto, and increasingly valuable identity data.