Hackers Demand $3 Million in Monero From Revolut, Threaten to Sell Customer Data
Key Takeaways
- •A group calling itself "iamnotavillain" demanded 6,000 XMR, roughly $3 million, from Revolut within 24 hours or it will sell the stolen identity documents and transaction records of hundreds of customers.
- •The perpetrators say they ran blockchain analysis to identify Revolut customers whose on-chain activity indicated substantial holdings, an account that aligns with investigator ZachXBT's assessment that the breach targeted high net worth users.
- •The data was handed over by Revolut in response to information requests sent through a compromised Italian government email domain with valid authentication, affecting at least 680 accounts over a period of months.
- •The stolen data includes names, birth dates, home addresses, passport and driving licence copies, verification selfies, account statements with IBANs, withdrawal records, and full transaction histories.
- •Revolut said it has not received any direct contact or demand from the group, described the number of affected customers as limited, and stated that customer funds and systems were untouched.

A criminal has given fintech firm Revolut a 24-hour deadline to pay a $3 million ransom in Monero or it will sell hundreds of customers' identity documents and transaction records to other criminals, the Financial Times reported.
The group, calling itself "iamnotavillain," posted the demand Wednesday on a website it set up for the purpose, asking for "6,000 XMR / $3,000,000" and warning that otherwise "all the data will be sold, and the blood will be on your hands." The tactic is data extortion: the stolen files themselves, rather than locked-down systems, serve as the leverage.
What distinguishes the breach is how the victims were chosen. The group told the FT it first ran blockchain analysis to identify Revolut customers whose on-chain activity suggested substantial holdings, then went after those specific accounts.
Monero is a privacy coin that obscures sender, recipient, and amount information using ring signatures and stealth addresses. Major crypto exchanges including Binance, Coinbase, and Kraken have delisted the asset.
Extortion groups request the token and sometimes discount their demands for victims who pay in it, according to blockchain intelligence firm TRM Labs, but most ransoms are still settled in Bitcoin, which the firm describes as "far easier to acquire, move, and convert at scale."
The Revolut breach
Revolut handed over the data itself, responding to information requests that arrived from a government agency's genuine email domain and carried valid authentication. The company has described the incident as "a sophisticated external impersonation scam."
The FT reports those requests came through a compromised Italian government email system and were made over a period of months, with at least 680 accounts affected.
The stolen data was extensive, spanning names, dates of birth, occupations, home addresses, passport or driving licence copies, the selfies customers submit for verification, account statements with IBANs and wallet references, withdrawal records, and full transaction histories. Fintechs like Revolut hold exactly this dossier because know-your-customer rules require identity checks before accounts can be opened — and unlike a password, a passport number cannot be reset once it leaks. The hackers have since shown the FT a screen recording of the files.
Blockchain investigator ZachXBT, who first circulated the customer notification, said the breach appeared "targeted at high net worth users," which aligns with the group's account of how it picked its victims. That combination of verified identity, home address, and proven holdings is the profile behind the rise in violent wrench attacks on known crypto owners — physical assaults in which criminals coerce holders into handing over their crypto.
Revolut said Wednesday evening that it "has not received any direct contact or demand from the individuals or group making these claims." The company has called the number of affected customers "limited," says funds and systems were untouched, and has declined to name the agency involved. Whether the 24-hour deadline passes without payment — and whether the agency behind the original requests is ever named — remains to be seen.