Hackers Behind Revolut Breach Demand 6,000 Monero, Set 24-Hour Deadline
Key Takeaways
- •A group calling itself "iamnotavillain" demanded 6,000 Monero, worth roughly $3 million, from Revolut within a 24-hour deadline, threatening to sell the stolen data to other criminal groups if unpaid.
- •Data connected to approximately 680 customer accounts was reportedly stolen, including passports, driving licences, identity-verification images and transaction histories, some of it linked to customers' crypto transactions.
- •Revolut said its core systems, databases and customer accounts were not directly breached, and that attackers submitted fraudulent requests while impersonating a real government entity via email.
- •The hackers reportedly analyzed blockchain transactions to identify which Revolut users were suspected of holding large cryptocurrency stashes, though these targeting details have not been independently verified.
- •Revolut stated it received no direct contact from the group, does not intend to pay a ransom, and has blocked the address involved while notifying the relevant government body, law enforcement and its regulator.

The hackers behind the recent data breach at global fintech platform Revolut have threatened to sell the stolen information to other criminal groups if they do not receive the 200 bitcoins they called for within 24 hours. The company has said the incident stemmed from a fraudulent impersonation scheme rather than a direct compromise of its systems, and that it does not intend to pay a ransom.
Hackers Demand 6,000 XMR
The group behind the attack, calling itself "iamnotavillain," published its demand online alongside a countdown clock, according to the Financial Times. It requested 6,000 XMR, a sum valued at roughly $3 million at the time of the report. Countdown-based deadlines are a standard pressure tactic in extortion attempts, designed to compress the target's decision window.
The choice of Monero is notable in an extortion case on the cryptocurrency front. Unlike the Bitcoin network, where transactions can be viewed openly on-chain, Monero is designed to offer greater privacy during transactions, making payments substantially harder to trace. That privacy focus is why privacy coins have been a recurring choice for extortion payments.
According to the Financial Times, the hackers stated that there had been no communication with Revolut up to the time the demand was published. The group also a brief video clip that appeared to be a screenshot of the customer data allegedly gathered during the incident.
Around 680 Customer Accounts Affected
Data allegedly connected to approximately 680 customer accounts was reportedly stolen in the breach. Revolut has stated that the incident did not involve a direct breach of its core systems, databases or customer accounts. Instead, the attackers allegedly submitted fake requests using an email application connected to a real government entity. The requests were framed as official business requests, and Revolut handed over the records before determining that they were fraudulent. Impersonating an official channel to trick an organization into handing over data is a recognized social-engineering vector that requires no compromise of a company's infrastructure.
The exposed material reportedly included passports, driving licences, identity-verification images and transaction histories. Additional information in some of the records was linked to customers' crypto transactions. Unlike a compromised password, identity documents cannot be reset, which is why leaked verification material can retain value to criminals well beyond the immediate incident.
Revolut said it blocked the address in question and informed the appropriate government body, law enforcement and the regulator.
Crypto Holdings Helped Attackers Pick Targets
The alleged use of blockchain analysis introduces a distinctive crypto element into the breach. The hackers reportedly studied blockchain transactions to uncover which Revolut users were suspected of holding large crypto stashes.
While a public blockchain can show wallet activity and transaction flows, considerably more information from an exchange or financial service is usually required to link a blockchain address to a specific person. In this case, the combination of blockchain transaction data and stolen customer records could provide an attacker with a clear picture of a user's identity and crypto assets. The details regarding target selection have not been verified by others. The episode illustrates why exchanges and fintech platforms treat the pairing of identity records with on-chain activity as among the most sensitive data they hold.
Revolut Rejects Direct Ransom Contact
There is a disconnect between what the attackers announced and what Revolut has reported. The company said it did not receive direct contact from the group claiming responsibility and does not intend to pay any ransom. Revolut added that affected customers were being supported and described the incident as the result of an external impersonation scheme.
Attention now turns to whether the group follows through on its stated threat once the deadline passes, and to what emerges from the law-enforcement and regulatory notifications Revolut says it has made.
The leak highlights a specific concern facing users in the crypto space: personal identity data, when merged with blockchain-related financial details, can be particularly useful to criminals. This information can be leveraged for targeted phishing, impersonation or further attempts to access digital assets.