Back to feed

Revolut hackers demand $3 million in Monero, threaten to sell customer data

2 min
Revolut hackers demand $3 million in Monero, threaten to sell customer data

This digest was compiled by AI from multiple sources — links to the originals are below.

Hackers are demanding $3 million in monero from Revolut within 24 hours, threatening to sell stolen customer data if the bank refuses to pay. At least 680 customer accounts were affected, with exposed data including identity documents and transaction histories. The group posted the demand Wednesday alongside a countdown clock, according to the Financial Times.

Key Facts

  • The hackers demand 6,000 XMR, worth $3 million, within 24 hours.
  • At least 680 Revolut customer accounts were affected by the breach.
  • The group calls itself “iamnotavillain” and posted the demand Wednesday with a countdown clock.
  • The hackers sent the FT a 60-second screen recording showing passports, driving licences, KYC photos, and transaction histories.
  • Attackers posed as government officials and sent fraudulent information requests that passed Revolut’s checks.

The Ransom Demand

The group, which calls itself “iamnotavillain,” posted the demand Wednesday alongside a countdown clock, the FT reported. It asked Revolut to send 6,000 XMR, a cryptocurrency designed to obscure transaction details. The hackers told the FT they chose their targets using blockchain analysis to find Revolut accounts with significant crypto holdings. The group sent the FT a 60-second screen recording that appeared to show some of the data it obtained. The video included passports, driving licences, photos used for know-your-customer checks and transaction histories, according to the newspaper.

Breach Mechanics

The breach came after attackers posed as government officials and sent requests for information that passed Revolut’s checks. Revolut handed over customer records before discovering the requests were fraudulent, according to notices previously sent to affected customers. Revolut previously told CoinDesk that it blocked the address used in the requests and notified the relevant government agency, law enforcement and regulators. The company said its systems and customer funds were unaffected.

Company Response

The hackers told the FT there had been no negotiations with Revolut at the time of publication. Revolut did not respond to CoinDesk’s request for comment by publication.