Revolut Hackers Demand $3M Monero Ransom, Threaten to Sell Customer Data: Report
A criminal group calling itself iamnotavillain has demanded 6,000 XMR (about $3 million) from Revolut, giving the company 24 hours to pay or face the sale of hundreds of customers' identity documents and transaction records, the Financial Times reported. The group says it used blockchain analysis to identify Revolut customers with substantial on-chain holdings; Revolut says it has not received any direct contact or demand from the perpetrators and describes the incident as resulting from a sophisticated impersonation scam.

Why It Matters
If accurate, the breach exposes verified identity documents paired with transaction histories and on-chain holdings for targeted customers, heightening risks of financial theft, identity fraud and physical attacks on known crypto holders. The attackers' use of Monero for extortion underscores how privacy-focused crypto is preferred in some ransom demands and complicates tracking and recovery efforts.
Key Facts
- Extortion demand: 6,000 XMR (around $3,000,000) within 24 hours
- Attacker name: iamnotavillain
- Source reporting: Financial Times
- Number of affected accounts reported: At least 680 accounts
- How attackers identified targets: Blockchain analysis to find customers with large crypto holdings
A criminal group calling itself iamnotavillain has posted a 24-hour ransom demand against Revolut, seeking 6,000 Monero (about $3 million) or it will sell hundreds of customers' identity documents and transaction records, the Financial Times reported. The group published the demand on a purpose-built website and warned that data would be sold if Revolut did not comply.
According to the FT, the attackers said they used blockchain analytics to identify Revolut customers whose on-chain activity suggested substantial crypto holdings, then focused their operation on those accounts. Blockchain investigator ZachXBT, who circulated a customer notification, said the breach appeared to be aimed at high-net-worth users, aligning with the group's account of its selection method.
Revolut has characterized the incident as stemming from a "sophisticated external impersonation scam," saying it provided data after receiving requests that came from a compromised Italian government email system and carried valid authentication. The FT reports those requests were made over several months. The stolen material shown to the FT reportedly included names, dates of birth, occupations, home addresses, copies of passports or driving licences, customer verification selfies, account statements with IBANs and wallet references, withdrawal records and full transaction histories.
Revolut told the FT it has not received any direct contact or demand from the individuals or group making the claims and described the number of affected customers as limited. The company also said funds and systems were untouched and declined to identify the government agency whose email domain was impersonated. The attackers' demand for payment in Monero — a privacy-focused coin that obfuscates transaction details and has been delisted by major exchanges such as Binance, Coinbase and Kraken — mirrors patterns noted by investigators who say extortionists sometimes prefer privacy coins even though many ransoms are still settled in Bitcoin.
Keep Reading
Polymarket Hires Ex-Zora CEO for Onchain Product Push

US sanctions Iran’s BitBank, saying it processes ‘Hormuz Safe’ Bitcoin payments

World launches self-custodial ‘super app’ World Money
