A large, dark vault door in a dimly lit room with
Crypto

Revolut Faces 6,000 XMR Ransom Demand After Customer Data Theft

Hackers set a 24-hour deadline and claim blockchain analysis was used to pick high-crypto-balance targets.

By Marcus Hale4 min read

A group calling itself “iamnotavillain” demanded 6,000 XMR, about $3 million, from Revolut within 24 hours and threatened to sell stolen customer data if unpaid. Revolut said its systems and customer funds were unaffected, but at least 680 accounts were impacted and the exposed records reportedly include KYC identity documents and transaction histories.

Revolut Hit With 6,000 XMR Ransom Demand After Customer-Data Theft

A hacking group calling itself “iamnotavillain” posted a ransom demand tied to a countdown clock, seeking 6,000 XMR, roughly $3 million, and giving Revolut 24 hours to pay. The group threatened to sell stolen Revolut customer data to other criminal groups if the deadline passed without payment.

The breach itself was linked to social engineering rather than a direct compromise of Revolut’s core infrastructure. Attackers allegedly impersonated government officials and submitted information requests that passed Revolut’s internal checks, prompting the company to hand over customer records before later determining the requests were fraudulent.

Revolut said its systems and customer funds were unaffected. The company also said it blocked the address used in the fraudulent requests and notified a government agency, law enforcement, and regulators.

The extortion mechanics are the point. A 24-hour timer compresses decision-making, and a Monero-denominated demand is optimized for reduced traceability versus transparent-chain payments.

What Was Exposed—and Why the Targeting Method Matters for Crypto Users

The reported blast radius is at least 680 Revolut customer accounts. The exposed data described includes passports, driving licences, photos used for know-your-customer checks, and transaction histories.

The catch is verification. The hackers provided a 60-second screen recording that appeared to show some of the obtained data, including identity documents and transaction histories, but the full scope and scale of exfiltration is not independently confirmed from the materials described.

For crypto users, the attackers’ claimed selection method is the more actionable detail than the headline ransom number. The group said it used blockchain analysis to identify Revolut accounts with significant crypto holdings, implying the dataset is being treated as a targeting layer, not just a pile of IDs.

That changes the downstream risk profile. KYC documents plus transaction histories can support identity fraud, account takeover attempts, and high-conviction phishing that references real activity. If the attackers’ “significant holdings” filter is real, the incentive shifts toward selective extortion and social engineering against a smaller set of higher-value individuals rather than broad, random fraud.

Countdown Clock, Monero, and the Next Moves to Monitor

The immediate marker is whether the stolen dataset surfaces for sale or is shared onward after the 24-hour deadline referenced in the demand. The threat is explicit: non-payment leads to distribution to other criminal groups, which typically widens both the number of actors and the number of attack paths.

Revolut’s next disclosure also matters. The confirmed scope remains “at least 680” affected accounts, and it is still unclear whether the data shown in the screen recording reflects a limited sample or a larger extraction. Any follow-up customer notifications, or a revised count, will clarify whether this stays contained or becomes a rolling exposure event.

Regulatory and law-enforcement follow-through is the other leg. Revolut has already said it notified a government agency, law enforcement, and regulators. Updates there can force additional disclosure, timelines, and remediation steps even if no ransom is paid.

On-chain monitoring is less clean here by design. The demand is denominated in XMR, a privacy-focused cryptocurrency designed to obscure transaction details, which limits traceability. Still, large, time-clustered Monero movements consistent with a 6,000 XMR payment are one of the few observable signals if funds move.

My Read: This Is a Playbook for Crypto-Selective Extortion, Not Just a Fintech Breach

The threshold that matters is not whether Revolut’s systems were “unaffected.” It is whether the stolen package is good enough to operationalize the attackers’ claimed filter: KYC identity plus transaction history plus a blockchain-analysis shortlist of higher-balance targets.

If the dataset is sold and the “significant holdings” claim holds up in subsequent targeting, this starts to look structural rather than narrative-driven. It becomes a repeatable playbook: use social engineering to pull regulated-fintech records, then use crypto heuristics to turn a generic breach into selective extortion with better hit rates.

Sources