Attacker claims Revolut data breach, demands $3M in Monero
Ransom threat follows Revolut leak
A criminal group has issued a ransom demand to Revolut, a banking and crypto asset platform. The attackers claim responsibility for a recent data breach and are asking for $3 million in Monero. Monero is a cryptocurrency often used for private transactions. The group stated that if the payment is not made, they will sell the stolen customer data to other criminals.
This demand is reportedly being made for the first time by the group, which operates under the name “iamnotavillain.” The organization launched its ransom website earlier this week. However, as of the time of reporting, formal negotiations have not yet started between the attackers and Revolut.
Conflicting accounts of contact
There is a significant disagreement between sources regarding whether Revolut has been contacted. The Financial Times reports that the attackers are making their demands public. In contrast, Reuters reports that Revolut has had no contact with the attackers and has not received any demands from them.
- The demand is for $3 million in Monero.
- A separate report claimed a demand for 10,000 Bitcoin.
- Reuters says Revolut has not been contacted by attackers.
- The attack reportedly used a compromised Italian government email.
How the breach happened
According to reports, the attackers were able to access Revolut systems by obtaining an Italian government email. They then posed as law enforcement officials to bypass security checks and retrieve data from customer accounts. A source familiar with the attack told Reuters that approximately 680 customers were affected. This source also stated that the attack did not impact Revolut’s core infrastructure, databases, or customer accounts.
Discrepancies in ransom amounts
Earlier reports from Coin Bureau suggested that attackers had demanded 10,000 Bitcoin, a figure valued at over $760 million at the current market rate. It is unclear whether this is the same group behind the $3 million Monero demand or a different entity. Coin Bureau did not reveal the specific usernames associated with the 10,000 Bitcoin demand, making it difficult to link the two reports.
Recent security issues in crypto
This incident follows a series of data breaches affecting crypto-related companies. Earlier this month, hardware wallet firm Trezor revealed that 80,000 users were exposed in a mailing breach. Additionally, password manager LastPass suffered a customer data leak in June after a third-party breach. These events highlight the ongoing security challenges faced by financial and crypto service providers.