NewsCryptoHackers Behind Revolut Data Breach Demand $3 Million Ransom in Monero

Hackers Behind Revolut Data Breach Demand $3 Million Ransom in Monero

Author: BitcoinKE·

Key Takeaways

  • A hacking group calling itself "iamnotavillain" gave Revolut 24 hours to pay 6,000 Monero tokens, worth about $3 million, or it would sell stolen customer data to other criminal groups, according to the Financial Times.
  • The breach reportedly affected about 680 customers, but Revolut's core infrastructure, databases, and customer accounts were not hacked.
  • Revolut said sensitive customer information was disclosed to an unauthorized third party after attackers submitted fraudulent requests using a legitimate government agency email domain.
  • The hackers claimed they used blockchain analysis of publicly recorded transaction data to identify Revolut accounts with significant crypto holdings.
  • Revolut stated it has had no direct contact with the alleged attackers and has not received a ransom demand.
Hackers Behind Revolut Data Breach Demand $3 Million Ransom in Monero

Hackers claiming responsibility for a data breach at Revolut, one of the United Kingdom's largest financial technology companies, have demanded a $3 million ransom in Monero and threatened to sell sensitive information belonging to hundreds of customers, according to reports, although the digital bank said it has received no direct ransom demand.

The group, calling itself "iamnotavillain," reportedly gave Revolut 24 hours to pay 6,000 Monero tokens, worth about $3 million, or it would sell the stolen information to other criminal groups. The ultimatum was posted online alongside a countdown, according to the Financial Times.

The demand reflects Monero's privacy-focused design. Every Monero transaction generates a random, one-time address so outsiders cannot link payments to a specific user's public wallet — a property that distinguishes the currency from pseudonymous public blockchains such as Bitcoin and has made it a recurring choice in extortion demands.

The breach is understood to have affected about 680 customers, while Revolut's core infrastructure, databases and customer accounts were not hacked, according to source familiar with the matter.

The company has said sensitive customer information was disclosed to an unauthorized third party after attackers submitted fraudulent requests using a legitimate government agency email domain. The stolen information reportedly includes identity documents and other sensitive customer records of at least 680 Revolut customers.

The hackers claim they chose their targets by using blockchain analysis — the examination of publicly recorded transaction data to trace wallet activity — to identify Revolut accounts with significant crypto holdings.

Revolut said it has not had direct contact with the alleged attackers and has not received a ransom demand, adding another layer of uncertainty to the extortion claims.

The incident highlights a growing cybersecurity risk for financial and crypto platforms, where attackers may not need to penetrate core banking systems if social-engineering attacks — which rely on deceiving people and exploiting legitimate processes rather than breaking technical defenses — can be used to obtain sensitive customer data from trusted channels. Identity documents are routinely used to verify customers across financial services, making them among the more sensitive types of personal data a breach can expose. In the United Kingdom, organizations must notify the Information Commissioner's Office within 72 hours of becoming aware of a personal data breach that is likely to pose a risk to individuals.