Hackers claiming responsibility for the Revolut customer data breach have issued a 24-hour ransom demand of 6,000 Monero (XMR), worth roughly $3 million, threatening to sell stolen identity and transaction records if the fintech does not pay. The group, calling itself iamnotavillain, published the ultimatum with a countdown clock, according to the Financial Times.
At least 680 customer accounts were affected. The attackers did not breach Revolut's internal systems directly; instead, they submitted fraudulent government requests using an email account tied to a legitimate government domain with valid authentication credentials. These requests passed Revolut's checks, causing the company to disclose customer records before discovering the requests were fraudulent. Revolut later blocked the email address and notified law enforcement, data-protection authorities and financial regulators.
Exposed data reportedly includes full names, dates of birth, home addresses, email addresses, phone numbers, passport or driving licence copies, verification selfies, IBANs, account status, withdrawal records, and complete transaction histories. Some records also contain Bitcoin wallet reference numbers and Bitcoin transaction histories. The hackers told the Financial Times they used blockchain analysis to select customers with substantial crypto holdings. On-chain investigator ZachXBT previously indicated the incident appeared to involve high-net-worth users.
Revolut has said its own systems and customer funds were not compromised and described the event as a sophisticated external impersonation scam. Britain’s Information Commissioner’s Office opened an investigation. The criminals chose Monero because its ring signatures, stealth addresses and Ring Confidential Transactions hide sender, recipient and amount. No negotiations between Revolut and the hackers had been reported by the time the Financial Times published its story.
The Financial Times did not specify whether U.S. customers were among those affected, but the combination of verified identity records and crypto transaction data raises targeted phishing and fraud risks. Revolut’s U.S. security guidance says the company will not unexpectedly call customers and ask for payments or security codes, and customers can verify suspicious contacts through the in-app support channel.