Smartphone displaying the Revolut name on screen while resting on a wooden surface.
SECURITY

Group Claiming Revolut Breach Demands $3M in Monero

Image credit: Unsplash

A group claiming responsibility for Revolut’s recent customer-data breach has demanded 6,000 Monero, worth about $3 million at the time of the ultimatum, and threatened to sell the information to other criminal groups if the fintech does not pay within 24 hours. Revolut says it has received no direct demand or communication from the group.

Group Posts 24-Hour Monero Demand

The group, calling itself iamnotavillain, posted the ultimatum online on Sept. 16 alongside a countdown clock. It demanded 6,000 XMR and threatened to sell confidential customer records if Revolut did not comply.

The group told the newspaper that it was using the website to issue its demand for the first time and that no negotiations with Revolut had taken place. Revolut separately told that it had received no direct contact or ransom demand from the people claiming responsibility.

Breach Involved Fraudulent Government Requests

Revolut confirmed on Sept. 12 that an unauthorized party obtained sensitive customer information after submitting fraudulent requests from an email account on a legitimate government agency domain. The company described the incident as an external impersonation scheme rather than a compromise of its core systems. A Revolut spokesperson said:

“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.”

Revolut said it blocked the address and notified the relevant government agency, law enforcement and regulators. The company has said its systems and customer funds were unaffected.

About 680 Customers Were Reportedly Affected

The incident is understood to have affected about 680 customers. Revolut itself has described the number as limited but has not publicly confirmed the 680 figure.

Customer notifications said potentially exposed information included birthdates, addresses, phone numbers and identity documents. Account statements, transaction histories and verification selfies may also have been disclosed.

The group claims blockchain analysis was used to identify customers with significant crypto holdings among those whose information it obtained. That account, including the scope of its targeting, has not been independently confirmed by Revolut.

Revolut Has Not Said It Will Pay

Revolut has not publicly indicated that it intends to pay the demand. At the time of reporting, there was also no confirmed evidence that the threatened customer-data sale had taken place.

The $3 million Monero demand remains a claim by the group, while the underlying unauthorized disclosure of customer information has been confirmed by Revolut. Investigations into how the fraudulent government requests were made and processed remain ongoing.

More For You

S&P Global to Acquire OpenZeppelin
BUSINESS

S&P Global to Acquire OpenZeppelin

S&P Global plans to acquire OpenZeppelin, expanding its blockchain security capabilities and strengthening its…

Sep 18, 2026 2 min read
Explore More News