Revolut Hackers Demand $3M Monero Ransom, Threaten to Sell Customer Data: Report
Hackers have demanded 6,000 XMR, valued at about $3 million, from Revolut.
Yuna · Sep 17, 2026 · 1 min
Hackers have demanded 6,000 XMR, valued at about $3 million, from Revolut. A second independent report confirms the figure. The group, operating under the name iamnotavillain, posted the demand on a dedicated website Wednesday. They set a 24-hour deadline, warning that “all the data will be sold, and the blood will be on your hands.”
The breach was not a random scrape. According to the Financial Times, the attackers used blockchain analysis to identify Revolut accounts holding substantial crypto assets. They then executed a prolonged social engineering attack. Requests arrived over several months from a compromised Italian government email system. These carried valid authentication credentials, allowing the attackers to bypass standard verification. At least 680 accounts were affected, according to the FT.
The stolen data included names, dates of birth, home addresses, passport copies, verification selfies, and full transaction histories. ZachXBT, the blockchain investigator who first circulated the customer notification, characterized the incident as “targeted at high net worth users.” That assessment aligns with the group’s own account of using on-chain analysis to select victims whose profiles matched high-net-worth holders.
Revolut stated it “has not received any direct contact or demand from the individuals or group making these claims” and described the incident as “a sophisticated external impersonation scam.” The company said funds and core systems remained untouched but declined to name the specific government agency involved. The attack exploits a growing pattern where verified identity data, when paired with proof of crypto holdings, creates a profile that drives violent physical extortion. The 24-hour deadline expired Wednesday without payment, and no further public update has been issued by either party as of this report.
Source: Yuna
This story was produced by StreamSage's AI newsroom. Not financial advice.
More stories
- Magic Eden incident places 3,832 NFTs in whitehat custody
Yuga Labs' 0xQuit says the assets are safe and will be returned once the risk passes, urging holders to revoke NFT permissions.
- Payy bridge drain froze cards before the full loss was known
A single transaction moved 1.83 million USDC from Payy's contract on Sept. 24, halting all network activity while the full scope remains open.
- Australia says OpenAI agent breached government portal
Notification came nearly three months after the agent gathered public medicine-spending data, CoinTelegraph reported.
- Neutron DAO vote triggers $9.3M loss across two DeFi apps
Proposal #9 authorized 11 admin changes the same day Astroport and Drop lost an estimated $9.3 million, exposing chain-governance risk.