Hackers demand $3 million in Monero from Revolut, threaten to sell stolen customer data
Hackers demand $3 million in Monero from Revolut or threaten to sell customer data
A hacking group calling itself "iamnotavillain" is demanding $3 million worth of monero from digital bank Revolut, according to a report from the Financial Times. The group says it will sell the stolen customer data to other criminal groups if Revolut does not pay within 24 hours.
Monero, known by its ticker XMR, is a cryptocurrency designed to hide the details of transactions, making it harder to trace than coins like bitcoin.
Key details from the FT report
- The hackers asked Revolut to send 6,000 XMR, a privacy-focused cryptocurrency, worth about $3 million.
- At least 680 Revolut customer accounts were affected by the breach.
- The hackers claim they used blockchain analysis (studying public crypto transaction records) to find Revolut customers who held significant amounts of crypto.
- The group sent the FT a 60-second screen recording that appeared to show passports, driving licences, identity verification photos, and transaction histories.
- As of publication, the hackers told the FT there had been no negotiations with Revolut.
How the breach happened
According to earlier notices sent to affected customers, the attackers posed as government officials and sent information requests that passed Revolut's checks. Revolut handed over customer records before discovering the requests were fraudulent. Revolut previously told CoinDesk it had blocked the address used in the requests, notified the relevant government agency, law enforcement, and regulators, and that its systems and customer funds were unaffected.
Revolut did not respond to CoinDesk's request for comment on the new ransom demand.
What is confirmed
- The ransom demand, the 24-hour deadline, and the request for 6,000 XMR come from the hackers themselves and were reported by the Financial Times.
- The figure of at least 680 affected accounts comes from the same FT report.
- The earlier breach method (fake government requests) and Revolut's response were previously confirmed to CoinDesk by Revolut.
What is still unclear
- CoinDesk was unable to independently verify the hackers' claims or the contents of the recording they shared with the FT.
- It is not known whether Revolut plans to pay or engage with the hackers.
- The full number of affected customers may be larger than 680, as this was the figure reported by the FT.
Why this matters
The incident highlights how criminals can combine social engineering (tricking employees into believing a request is real) with blockchain analysis to target crypto users specifically. The choice of monero as the ransom payment reflects a broader trend of hackers seeking cryptocurrencies that are harder to trace.