CRYPTOCURRENCY NEWS

Revolut Hackers Demand $3M in Monero, Threaten Data Sale

A group calling itself iamnotavillain has demanded 6,000 XMR, described as roughly $3 million, from Revolut, threatening to sell stolen customer data including identity documents and transaction histories if the fintech company does not pay within 24 hours.

Share:

What the Revolut hackers’ $3 million Monero demand alleges

CoinDesk, citing the Financial Times, reports that iamnotavillain set a 24-hour deadline for payment of the demand, threatening to publish or sell the data if Revolut does not comply. For related coverage, see Hamas Military Wing Told Donors to Avoid Binance: Report.

Reported ransom demand
6,000 XMR
Reported as approximately $3 million, with a 24-hour deadline. Attribution: CoinDesk citing the Financial Times.

According to the same reporting, the threatened material includes passports, driving licences, KYC photos, and transaction histories. The claims about what the group actually controls remain unconfirmed; no independent review of the alleged data or an on-chain payment address has been publicly verified. For related coverage, see House Tax Committee Advances Crypto Tax Bill After Clarity Act Loss.

CoinDesk reports that at least 680 Revolut customer accounts were affected in the alleged incident, citing the Financial Times.

Reported affected accounts
At least 680
Customer accounts reported affected; the underlying incident claims remain unconfirmed.

CoinDesk attributes to Revolut the statement that its systems and customer funds were unaffected. The company said it blocked the address used in the requests and notified the relevant government agency, law enforcement, and regulators. Revolut’s public system-status page was not directly accessible for independent review at time of writing.

A separate, unconfirmed detail reported by CoinDesk is that the breach may have originated from fraudulent information requests posed as coming from government officials. That alleged vector connects to a documented vulnerability: Revolut previously shared passport and customer bitcoin data after receiving what turned out to be a fraudulent government request, a pattern that highlights how KYC-rich fintechs can be targeted through impersonation rather than direct system intrusion.

Why Monero matters as the demanded payment currency

The demand for XMR rather than Bitcoin is deliberate. The Monero Project states that RingCT hides transaction amounts by default and that minimum ring-signature sizes make all Monero transactions private by protocol mandate, meaning senders, receivers, and amounts are not publicly traceable on-chain. That is precisely the property extortionists value: it removes the investigative lever that law enforcement has used to trace Bitcoin ransom payments in high-profile cases.

The choice of Monero also carries regulatory weight for Revolut specifically. The company has been expanding its stablecoin products across Europe, including rolling out its EURR euro stablecoin and opening EURR access in Denmark, Poland, and Portugal. An extortion demand denominated in a privacy coin creates additional compliance friction in jurisdictions that already treat Monero with heightened regulatory scrutiny.

What Revolut customers should watch for next

The most important signal to monitor is whether Revolut issues a direct customer disclosure with specifics: which accounts were affected, what data categories were exposed, and what remediation steps are in place. CoinDesk reports that Revolut said notices were sent to affected customers, but those notices were not publicly accessible for review at time of writing.

If a data exposure is confirmed, the practical risk for affected customers centers on identity documents and KYC photos rather than funds. Revolut has stated that customer funds are unaffected. Customers who believe they may be among the reported group of affected accounts should rely on official Revolut communications for incident-specific guidance and treat unexpected contact from parties claiming knowledge of their account details with heightened suspicion.

The alleged use of fraudulent government impersonation as an access vector, if confirmed, would fall squarely within the category of social-engineering attacks that security agencies have repeatedly flagged. Verified identity documents command high prices on underground markets regardless of whether a ransom is paid, and the intersection of privacy-coin infrastructure and illicit finance has drawn sustained regulatory attention that will likely shape how authorities respond here.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Stay ahead of the market

Get daily crypto insights delivered to your inbox.

Related Articles

View all →