HomeLBank News Center
Revolut Hackers Demand $3M Monero Ransom, Threaten to Sell Customer Data: Report
revolut-hackers-demand-3m-monero-ransom-threaten-to-sell-customer-data-report
Revolut Hackers Demand $3M Monero Ransom, Threaten to Sell Customer Data: Report
The group says it chose whom to target by scanning the blockchain for Revolut accounts holding significant crypto.
2026-09-17 Source:decrypt.co

In brief

  • A group calling itself iamnotavillain has demanded 6,000 XMR, around $3 million, within 24 hours.
  • It says it used blockchain analysis to find Revolut accounts with large crypto holdings.
  • Revolut says it has received no direct contact or demand.

A criminal group has put a 24-hour clock on Revolut, demanding $3 million in Monero or it will sell hundreds of customers' identity documents and transaction records to other criminals, the Financial Times reported.

The demand, posted Wednesday on a website the group set up for the purpose, asks for "6,000 XMR / $3,000,000" and warns that otherwise "all the data will be sold, and the blood will be on your hands."

Monero, a privacy coin, obfuscates sender, recipient and amount information using ring signatures and stealth addresses. It has been delisted by major crypto exchanges including Binance, Coinbase and Kraken.

Extortion groups ask for it and sometimes discount their demands for victims who pay in it, according to TRM Labs, but most ransoms are still settled in Bitcoin, which it describes as "far easier to acquire, move, and convert at scale."

What distinguishes this breach is how the victims were chosen. The group told the FT it ran blockchain analysis first, picking out Revolut customers whose on-chain activity suggested substantial holdings, and then went after those specific accounts.

The Revolut breach

Revolut handed over the data itself, responding to information requests that arrived from a government agency's genuine email domain and carried valid authentication. The company has described it as "a sophisticated external impersonation scam."

The FT reports those requests came via a compromised Italian government email system and were made over a period of months, with at least 680 accounts affected.

The stolen data was extensive, including names, dates of birth, occupations, home addresses, passport or driving licence copies, the selfies customers submit for verification, account statements with IBANs and wallet references, withdrawal records and full transaction histories. The hackers have since shown the FT a screen recording of the files.

Myriad: Where does crude oil go next? Click to make your prediction.

Blockchain investigator ZachXBT, who first circulated the customer notification, said the breach appeared "targeted at high net worth users," which aligns with the group's account of how it picked them. That combination of verified identity, home address and proven holdings is the profile behind the rise in violent wrench attacks on known crypto owners.

Revolut said on Wednesday evening it "has not received any direct contact or demand from the individuals or group making these claims." It has called the number of affected customers "limited," says funds and systems were untouched, and has declined to name the agency involved.