The group behind the Revolut hack has demanded 6,000 Monero (XMR), worth approximately $3 million, after obtaining sensitive information linked to at least 680 customers. The attackers, who identify themselves as “iamnotavillain,” threatened to sell the records to other criminal groups unless the ransom was paid within 24 hours.
The demand was published Wednesday alongside a countdown clock, according to the Financial Times. The alleged attackers claimed they obtained the information after fraudulent requests were submitted through an email account using the domain of a legitimate government agency.
The incident has raised further concerns about the security of customer identity and financial information because the stolen material reportedly includes passports, driving licences, identity-verification photographs, addresses and transaction histories. Revolut has maintained that its internal systems and customer funds were not compromised.
Revolut hack triggers $3M Monero ransom demand
The latest development in the Revolut hack emerged after the attackers publicly posted their ransom demand and threatened to make the stolen records available to other criminals.
At the reported value of roughly $500 per XMR, the 6,000 Monero demand amounts to about $3 million. The attackers chose Monero, a cryptocurrency designed to provide greater transaction privacy by obscuring information about senders, recipients and transaction amounts.
The group reportedly gave Revolut 24 hours to make the payment. However, there was no indication that negotiations had begun when the Financial Times published its report.
Revolut has also not confirmed that the attackers have full control of the information they claim to possess. Reuters reported that the company had not received a direct ransom demand from the group.
The attackers provided the Financial Times with a 60-second screen recording that appeared to show some of the allegedly stolen material. According to the report, the footage included passports, driving licences, photographs submitted during know-your-customer checks and customer transaction histories.
The scale of the Revolut hack remains relatively small compared with the company’s overall customer base. Revolut has described the affected portion as a “very limited” part of its customers.
How the Revolut hack exposed customer records
The Revolut hack did not reportedly involve a conventional breach of the fintech’s internal infrastructure. Instead, attackers allegedly impersonated government officials and submitted fraudulent requests for customer information.
The requests reportedly originated from an email account operating under the domain of a legitimate government agency. Because the requests carried valid domain-authentication credentials, they passed the checks Revolut used to determine whether the communications were legitimate.
Revolut subsequently provided customer information before discovering that the requests were fraudulent.
The company described the incident as a “sophisticated external impersonation scam” and said its systems remained secure. After identifying the activity, Revolut blocked the email address and contacted the relevant government agency, law enforcement, data-protection authorities and financial regulators.
The information reportedly disclosed included customers’ full names, dates of birth, occupations, residential addresses, email addresses and telephone numbers. Some records also contained copies of passports or driving licences and selfies submitted as part of identity verification.
Financial information was also reportedly included. The exposed records contained International Bank Account Numbers, account-opening dates, account status, withdrawal records and complete transaction histories. Some account statements also contained Bitcoin wallet reference numbers and records of Bitcoin transactions.
Revolut distinguished the identity-check photographs from biometric facial telemetry data, which it said was not included in the disclosure. The company also said private keys, passwords, security codes and complete payment-card details were not among the exposed information.
Blockchain analysis reportedly shaped Revolut hack targets
Another significant element of the Revolut hack is the attackers’ claim that blockchain analysis helped them identify customers with substantial cryptocurrency holdings.
According to the group, blockchain data was used to select customers who appeared to control large amounts of cryptocurrency. If accurate, that would suggest the attackers were not simply collecting customer information indiscriminately but were using financial activity to identify potentially valuable targets.
On-chain investigator ZachXBT had previously suggested that the affected accounts appeared to include high-net-worth users. Revolut, however, had not independently confirmed that assessment.
The hackers’ claim has also not been independently verified.
Public blockchains such as Bitcoin and Ethereum expose transaction activity, wallet balances and transfers between addresses. Analysts can sometimes connect those blockchain records to individuals when a cryptocurrency exchange, financial institution or other service maintains information linking a customer to a particular wallet.
That makes the combination of identity documents and cryptocurrency transaction information particularly significant in the Revolut hack.
A stolen passport or driving licence can establish a person’s identity, while transaction histories and wallet references can potentially reveal elements of their cryptocurrency activity. Together, those records could provide criminals with detailed information for targeted impersonation or further social-engineering attempts.
Monero adds another layer to the Revolut hack
The attackers’ decision to demand Monero in the Revolut hack also highlights the cryptocurrency’s privacy-focused design.
Unlike transparent blockchain networks where transaction details can generally be viewed publicly, Monero incorporates privacy mechanisms designed to obscure transaction participants and amounts. Its technology includes ring signatures, stealth addresses and Ring Confidential Transactions.
Those features can make it more difficult to trace payments through the blockchain.
However, the use of Monero by criminals does not mean that the cryptocurrency itself or all of its users are involved in illegal activity. Monero is also used by individuals who seek greater financial privacy.
The Revolut hack nevertheless demonstrates why privacy-focused cryptocurrencies can become part of ransom demands. Investigators attempting to follow illicit payments may face greater obstacles when funds are converted into assets designed to conceal transaction details.
The incident also illustrates a broader security issue for crypto users. Even when a company’s core infrastructure remains intact, attackers may attempt to exploit trusted communication channels, identity-verification processes or third-party systems to obtain sensitive customer information.
For customers affected by the Revolut hack, the exposure of identity and financial records could create risks beyond the initial incident. Criminals possessing genuine personal information can use it to make phishing messages, phone calls or other impersonation attempts appear more credible.
The presence of accurate information about a customer’s account or transaction history does not, by itself, prove that a message or caller is genuinely associated with Revolut.
Revolut’s security guidance says customers should use the company’s in-app support channels to verify suspicious communications. The company also says it will not unexpectedly call customers and ask them to make payments or disclose verification and security codes.
The Revolut hack is now being examined alongside the wider question of how fraudulent requests using legitimate government communication infrastructure were able to pass verification procedures.
Authorities and regulators have been notified, while the company continues to work with affected customers and relevant agencies. The attackers’ ransom deadline adds another layer to an incident that began not with a direct compromise of Revolut’s systems, but with the alleged abuse of a trusted government email channel.
For now, the central claims made by the attackers, including the full extent of the stolen information and their alleged method of selecting cryptocurrency holders, remain subject to verification.
The Revolut hack therefore remains both a customer-data breach and an evolving criminal investigation, with the ransom demand adding pressure as authorities work to determine how the information was obtained and what may happen to it next.