Hackers claiming responsibility for a Revolut data breach have demanded 6,000 Monero, worth about $3 million, and threatened to sell confidential customer records within 24 hours.
The group, calling itself iamnotavillain, published the demand alongside a countdown clock. It claims to hold information linked to about 680 Revolut customers. However, Revolut says it has not received a direct ransom demand from the alleged attackers.
The incident adds a new cryptocurrency angle to a breach that has already raised concerns about customer data protection and impersonation scams.
How the Revolut Breach Happened
The attackers allegedly did not penetrate Revolut’s core systems. Instead, they used a compromised Italian government email channel while posing as law enforcement officials.
Revolut previously said an unauthorized party used a legitimate government agency domain to submit fraudulent information requests. The company then provided data before identifying the deception.
Reportedly exposed information includes:
- Passport and driver’s license details
- Addresses, phone numbers and email information
- Verification images and selfies
- Account and transaction records
- Information connected to cryptocurrency activity
The attackers allegedly selected some targets after using blockchain analysis to identify customers with substantial crypto holdings.
Why the Hackers Want Monero
The ransom demand specifically calls for Monero, a cryptocurrency designed to provide greater transaction privacy than transparent blockchains such as Bitcoin.
The group demanded 6,000 XMR, describing the payment as roughly $3 million. It threatened to sell the customer information to other criminal groups if Revolut does not pay within the stated deadline.
However, the ransom demand remains an allegation from the group claiming responsibility. Revolut has said its systems and customer funds remain unaffected.
The breach has also attracted regulatory attention. The UK’s data protection regulator has confirmed that it received a report concerning the incident and is assessing the information provided.
The case highlights a broader cybersecurity risk for financial and crypto companies. Attackers may not always need to defeat technical defenses if they can exploit trusted communication channels and impersonate authorized officials.