Home | FCA & regulatory news | British English edition
Trade Hub UK

Independent coverage of UK markets, FCA policy and institutional trading

AD LSEG Data AD CME Group Education AD Bank of England Statistics AD Investing.com Markets
Digital Assets

Revolut Hackers Demand $3M in XMR, Give 24 Hours to Pay

  • Revolut hackers demand 6,000 Monero worth around $3 million from the fintech firm.

  • Hackers threaten to sell stolen customer data if Revolut refuses the ransom, said "The blood will be on Revolut's hands.”

  • Around 680 customer accounts were reportedly affected, mainly in Switzerland and France.

Hackers claiming responsibility for a Revolut data breach are demanding a $3 million ransom in Monero (XMR) and have given the fintech firm 24 hours to pay. The group says it will sell the stolen customer data to other criminals if Revolut refuses to pay.
Meanwhile, the Revolut team stated that the company had never received a direct extortion demand from the cybercriminals.

Hackers Gave Revolut 24-Hour Deadline

The group, calling itself “iamnotavillain,” posted the ransom demand, asking Revolut to pay 6,000 XMR, worth around $3 million. The hackers reportedly set a 24-hour deadline and threatened to sell the information if the payment is not made.

“The blood will be on Revolut’s hands.”

The hackers sent the FT a 60 second recording that appeared to show some of the stolen information. The exposed data reportedly includes passports, driving licences, KYC photos and transaction histories, including crypto transaction records.

Even the former Mt. Gox CEO Mark Karpeles has also said he was among customers notified about the incident.

How Did the Revolut Breach Happen?

The breach did not involve a direct attack on Revolut’s servers. Instead, hackers used fake identities and social engineering to trick the company.

The attackers reportedly accessed an email account linked to an Italian government agency and used it to send fake European Investigation Orders to Revolut.

Since the requests appeared to come from law enforcement officials, they passed Revolut’s checks. The company then unknowingly shared customer information before finding out that the requests were fake.

At least 680 customer accounts were reportedly affected by the breach. Most of the targeted customers are in Switzerland and France, with others in the UK and Germany.

Response From Revolut Team

Revolut said it has not negotiated with the hackers and has not paid any ransom. The company also said it never received a direct ransom demand from the attackers.

The $3 million Monero (XMR) demand and 24-hour deadline were posted publicly on a new website by the hacker group. The group said that it chose to publish the threat online instead of contacting Revolut directly.

This means there have been no ransom talks between the hackers and Revolut.

The company is instead focused on containing the incident, working with law enforcement and supporting affected customers.

Was this writing helpful?

Trust with CoinPedia:

CoinPedia has been delivering accurate and timely cryptocurrency and blockchain updates since 2017. All content is created by our expert panel of analysts and journalists, following strict Editorial Guidelines based on E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness). Every article is fact-checked against reputable sources to ensure accuracy, transparency, and reliability. Our review policy guarantees unbiased evaluations when recommending exchanges, platforms, or tools. We strive to provide timely updates about everything crypto & blockchain, right from startups to industry majors.

Investment Disclaimer:

All opinions and insights shared represent the author's own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.

Sponsored and Advertisements:

Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.