Timeline
- 7.5
Revolut hit with $3M Monero ransom demand over customer data breach
A group calling itself "iamnotavillain" has publicly demanded $3 million in Monero (XMR) from fintech Revolut, threatening to sell stolen customer data to other criminals if it is not paid. The ransom site launched this week, but Reuters reports Revolut has so far had no contact with or demands from the attackers, and negotiations have not begun. It marks one of the most prominent ransomware-style extortion attempts against a major digital bank, and the choice of Monero underscores how privacy coins remain the preferred settlement channel for extortion. The breach also highlights the growing social-engineering risk facing crypto-adjacent financial platforms, where a single spoofed government email can expose customer records. Attackers reportedly gained access by using a legitimate Italian government email domain to impersonate law enforcement and bypass Revolut's security checks; Reuters cites a source saying roughly 680 customers were affected and that Revolut's core infrastructure, databases and customer accounts were not impacted. Earlier reports from Coin Bureau claimed a 10,000 BTC demand (worth over $760 million at current prices), and it is unclear whether that claim involved the same group.
- 7.5
Revolut hackers demand $3M in Monero, threaten to sell customer data
A hacker group calling itself "iamnotavillain" is demanding 6,000 monero (XMR), worth about $3 million, from Revolut within 24 hours, threatening to sell stolen customer data to other criminal groups if the payment is not made, according to the Financial Times. At least 680 Revolut customer accounts were affected, and the group sent the FT a 60-second screen recording appearing to show passports, driving licences, KYC photos and transaction histories. This is a confirmed data breach at a major digital bank with more than 80 million customers, exposing identity documents and transaction histories for users the attackers specifically selected for their large crypto holdings. It highlights how KYC and identity data held by regulated fintechs can become a targeted asset, and it reinforces monero's role as the preferred settlement rail for extortion demands. The attackers told the FT they used blockchain analysis to identify Revolut accounts holding significant crypto assets, and they said no negotiations had taken place at the time of publication. The breach reportedly stemmed from attackers impersonating government officials and sending information requests that passed Revolut's verification checks; Revolut says it blocked the address used, notified the relevant government agency, law enforcement and regulators, and that its systems and customer funds were unaffected.
- 7.5
Revolut customer data leak: attackers demand 10,000 BTC ransom
UK-based fintech Revolut confirmed that attackers used a legitimate government-agency email domain to submit fraudulent requests for customer information, and those attackers are now publishing leaked identity documents while allegedly demanding 10,000 BTC (roughly $780 million) to stop further releases. Revolut has not confirmed the ransom demand and has not authenticated the material circulating online. The alleged 10,000 BTC demand is one of the largest crypto-denominated ransom figures ever attached to a fintech breach, and it shows how a simple email-impersonation trick can defeat the verification checks of a bank that holds both fiat and crypto assets. For the crypto sector, the possible exposure of transaction histories belonging to high-profile holders — including former Mt. Gox CEO Mark Karpelès — raises concern about targeted attacks on wealthy on-chain users. Potentially exposed data includes names, dates of birth, addresses, email addresses and phone numbers, plus copies of passports and driving licences, while customer notifications also referenced account statements, IBANs, withdrawal records and full transaction histories including BTC activity. Revolut says the number of affected customers was "very limited" and that its systems and customer funds were unaffected, while the 10,000 BTC figure remains unverified and some observers, including analyst Max Karpis, doubt the demand is genuine because such a payment would be traceable on-chain.
- 7.5
Revolut data breach: fake government email exposed customer passports and transaction histories
Revolut disclosed that a fraudster used a legitimate government agency email domain to submit fraudulent requests for customer information, which passed the company's authentication checks, exposing copies of passports, verification selfies and full transaction histories. The fintech said it detected the scheme, blocked the address, alerted the government agency, law enforcement and financial regulators, and notified the limited number of affected customers on Friday. The incident shows how a social-engineering attack can defeat identity-verification controls at a major fintech without any technical intrusion, undermining confidence in the mandatory KYC data that platforms collect. It matters because Revolut holds identity documents, selfies, IBANs and transaction data for tens of millions of users, and some of that exposed data can be used for account-takeover attempts, targeted phishing and extortion against high-net-worth individuals. The fraudulent requests appeared to come from a real government agency's domain, meaning the attacker did not need to spoof the address but exploited the trust the domain carries, and detection only happened after the data had already been released. Revolut said its systems and customer funds were unaffected, crypto sleuth ZachXBT characterised the incident as limited in size and aimed at high-net-worth users, and reported exposed fields also include contact details, birth dates, occupations, account statements, IBANs and Bitcoin-related information.
- 8.5
Revolut hands passports and Bitcoin data to fake government request
Revolut disclosed that it turned over sensitive customer data — including passport and driver's license copies, verification selfies, IBAN and wallet reference numbers, and full Bitcoin transaction histories — after receiving a fraudulent information request sent from a legitimate government agency's email domain. A Revolut spokesperson called it "a sophisticated external impersonation scam," said a "limited" number of customers were affected, and stated that its systems and customer funds were unaffected, while declining to say how many users were hit or which agency was impersonated. The leak links real-world identities and residential addresses directly to onchain transaction histories, which is exactly the combination that enables physical targeting of crypto holders, and it intensifies scrutiny of how fintechs and exchanges store and release KYC data. Because Revolut is weighing an IPO and recently launched its EURR stablecoin, the incident carries both regulatory and reputational weight for a major crypto-adjacent firm. The fraudulent email passed the agency domain's authentication checks, which is why Revolut treated it as genuine; the company said no biometric facial telemetry, passwords, PINs or private keys were exposed, so no funds were directly lost. Revolut blocked the email address and notified the impersonated agency, law enforcement and regulators, but has not explained why it released records without confirming the request through a second channel.