Key Takeaways
- A hacker group identifying as “iamnotavillain” issued a 24-hour ultimatum demanding 6,000 Monero (approximately $3 million) from Revolut
- Fraudulent government data requests successfully bypassed Revolut’s security protocols, affecting a minimum of 680 customer accounts
- Compromised information encompasses identity documents including passports and driver’s licenses, identification photos, and complete transaction records
- Threat actors leveraged blockchain analytics to specifically identify customers holding substantial cryptocurrency assets
- Revolut maintains that its core infrastructure and customer funds remain secure
Cybercriminals are extorting Revolut for $3 million following a sophisticated social engineering attack that resulted in unauthorized access to sensitive customer information.
Revolut Hackers Demand $3 Million in Monero, Set 24-Hour Deadline
Hackers calling themselves “iamnotavillain” demanded 6,000 XMR, worth about $3 million, from Revolut and threatened to sell stolen customer data to other criminal groups unless paid within 24 hours. The breach… pic.twitter.com/AO742ZpipZ
— Wu Blockchain (@WuBlockchain) September 17, 2026
The threat actors, operating under the moniker “iamnotavillain,” publicly announced their ransom demand on Wednesday, accompanied by a 24-hour countdown timer. They warned that failure to comply would result in the stolen database being distributed to other criminal organizations.
The extortion amount equals 6,000 Monero tokens, a privacy-focused digital currency specifically engineered to obscure transaction trails including sender identities, recipient addresses, and transfer amounts.
Anatomy of the Security Incident
Rather than exploiting technical vulnerabilities in Revolut’s infrastructure, the perpetrators employed social engineering tactics by impersonating law enforcement or regulatory officials. They submitted fraudulent information requests utilizing what appeared to be authentic government email domains.
These deceptive requests successfully cleared Revolut’s verification procedures, prompting the financial technology company to release customer information before identifying the scam. Upon detection, Revolut immediately blacklisted the compromised email address and notified law enforcement authorities, financial regulators, and the impersonated government entity.
While a minimum of 680 customer accounts were compromised, Revolut characterized this figure as representing a “very limited” fraction of its total user population.
The breadth of exfiltrated data is concerning. Compromised records contain complete names, birth dates, residential addresses, email contacts, telephone numbers, passport documentation, driver’s licenses, and verification selfies uploaded during account creation.
Additionally, financial account details were exposed, encompassing bank account identifiers, account establishment dates, comprehensive transaction logs, and Bitcoin wallet reference codes.
Revolut emphasized that encryption keys, authentication passwords, two-factor security codes, and complete payment card credentials were not included in the compromised dataset.
Targeted Selection of Victims
In communications with the Financial Times, the hackers revealed they employed blockchain forensics to pinpoint Revolut users maintaining substantial cryptocurrency portfolios. Blockchain investigator ZachXBT had earlier speculated that the breach specifically targeted affluent users.
Transparent blockchain networks enable anyone to examine wallet balances, historical transactions, and fund movements between addresses. When this publicly accessible blockchain data is cross-referenced with personal identification records maintained by financial platforms, it can completely deanonymize an individual’s cryptocurrency activities.
The leaked Revolut information reportedly bridges both elements—blockchain activity and personal identity—potentially exposing affected customers to sophisticated phishing attacks and targeted fraud schemes.
Monero was selected as the ransom currency precisely because its built-in privacy mechanisms significantly complicate law enforcement tracing efforts compared to transparent cryptocurrencies like Bitcoin or Ethereum.
According to the Financial Times, no dialogue between Revolut representatives and the extortionists had occurred as of their report’s publication. Revolut has declined to indicate whether it intends to engage with the ransom demand.


