Revolut hackers demand $3 million in Monero, threaten to sell customer data
A hacker group calling itself “iamnotavillain” has demanded 6,000 Monero (about $3 million) from Revolut within 24 hours, threatening to sell stolen customer data to other criminal groups if the firm does not pay, the Financial Times reports. The attackers claim they accessed at least 680 customer accounts and provided a short video purportedly showing identity documents and transaction histories.

Why It Matters
The breach exposes sensitive personal and financial records of hundreds of customers and highlights how attackers may combine social-engineering and blockchain analysis to target crypto holders, raising risks for digital-asset platforms and their users.
Key Facts
- Attacker name: iamnotavillain
- Ransom demand: 6,000 XMR (about $3 million) within 24 hours
- Number of affected accounts: At least 680
- Types of exposed data: Passports, driving licences, KYC photos, transaction histories
- Method used to identify targets: Blockchain analysis to find accounts with significant crypto holdings (as claimed by attackers)
A hacking group identifying itself as iamnotavillain told the Financial Times it has stolen data from Revolut customers and is demanding 6,000 Monero (roughly $3 million) within 24 hours, or it will sell the information to other criminal groups. The group posted a countdown alongside its demand and provided the FT with a 60-second screen recording that it said showed some of the files it obtained. According to the report, at least 680 Revolut customer accounts were impacted. The material shown in the video reportedly included identity documents such as passports and driving licences, photos used for know-your-customer checks, and transaction histories. The attackers told the FT they used blockchain analysis to single out Revolut accounts holding substantial cryptocurrency balances. Revolut has said it blocked the address used to send the fraudulent requests and informed the relevant government agency, law enforcement and regulators. The company also stated that its systems and customer funds were not affected. Notices previously sent to impacted customers indicated the breach began after attackers impersonated government officials and submitted requests that initially passed Revolut’s verification checks, leading the firm to release records before the requests were identified as fraudulent. At the time the FT published the story, the hackers said there had been no negotiations with Revolut. CoinDesk reached out to Revolut for comment but did not receive a response by the time of publication.
Keep Reading

Why Thrive, Founders Fund, and Antonio Gracias are betting on hearing aids

How Fortell is using AI (and $163M) to crack a hearing aid monopoly

Anthropic and OpenAI want to embed safety evaluators. Will they really be independent?
