Revolut Faces $3M Monero Ransom Demand Following Major Customer Data Breach

Revolut Faces $3M Monero Ransom Demand Following Major Customer Data Breach
Key Points A hacker group identified as “iamnotavillain” has issued a ransom demand for 6,000 Monero (approximately $3 million) from Revolut with a 24-hour deadline A minimum of 680 customer accounts were compromised following fraudulent government data requests that bypassed Revolut’s verification protocols Compromised information encompasses passport details, driver’s licenses, identification photographs, and comprehensive transaction records The cybercriminals employed blockchain analysis techniques to identify customers holding substantial cryptocurrency assets Revolut maintains that its core infrastructure and customer funds remain secure Cybercriminals have issued a $3 million ransom demand to Revolut following the theft of customer information through a sophisticated government impersonation scheme. Revolut Hackers Demand $3 Million in Monero, Set 24-Hour Deadline Hackers calling themselves “iamnotavillain” demanded 6,000 XMR, worth about $3 million, from Revolut and threatened to sell stolen customer data to other criminal groups unless paid within 24 hours. The breach… pic.twitter.com/AO742ZpipZ — Wu Blockchain (@WuBlockchain) September 17, 2026 The criminal organization, operating under the moniker “iamnotavillain,” published their ransom demand on Wednesday accompanied by a digital countdown timer. Revolut was given 24 hours to comply with the payment demand, or the stolen customer records would be sold to additional criminal entities. The ransom amount specified is 6,000 Monero, a privacy-focused cryptocurrency that conceals transaction information such as sender identity, receiver details, and transfer amounts. The Attack Method Explained The cybercriminals avoided a direct system intrusion. Their approach involved masquerading as government representatives and submitting data requests through what seemed to be an authentic government email domain. These fraudulent requests successfully passed through Revolut’s verification procedures, resulting in the company releasing customer information before identifying the deception. After detection, Revolut immediately blocked the suspicious email address and notified law enforcement authorities, regulatory bodies, and the impersonated government organization. A minimum of 680 customer accounts were impacted, though Revolut characterized this as representing a “very limited” fraction of its total user population. The scope of stolen information is significant. Compromised data encompasses complete names, birth dates, residential addresses, email contacts, telephone numbers, passport documentation, driver’s licenses, and identification selfies provided during verification processes. Financial account information was also obtained, including bank account identifiers, account creation dates, complete transaction histories, and Bitcoin wallet reference codes. Revolut has verified that cryptographic private keys, account passwords, security authentication codes, and complete payment card credentials were not included in the exposed data. Targeted Selection of Victims The hackers disclosed to the Financial Times that they utilized blockchain analysis tools to pinpoint Revolut users possessing significant cryptocurrency holdings. Blockchain investigator ZachXBT had previously indicated that the breach targeted high-net-worth individuals. Public blockchain networks can disclose wallet balances, transaction patterns, and transfers between wallet addresses. When this blockchain data is correlated with personal identification records maintained by financial institutions, it can reveal an individual’s complete cryptocurrency activity profile. The leaked Revolut information appears to establish both connections, potentially increasing the vulnerability of affected customers to sophisticated targeted fraud schemes. Monero was selected as the ransom payment method due to its enhanced privacy characteristics, which significantly complicate investigative tracking compared to Bitcoin or Ethereum. According to the Financial Times, no discussions between Revolut and the cybercriminals had occurred as of their report’s publication. Revolut has not publicly indicated whether they intend to engage with the ransom demand. The post Revolut Faces $3M Monero Ransom Demand Following Major Customer Data Breach appeared first on Blockonomi.

Take Your Experience to the Next Level

New

Download our mobile app for a faster and better experience.

Comments

0
U

Join the discussion

Sign in to leave a comment

0:000:00