Hackers claiming responsibility for the recent Revolut data breach have demanded approximately $3 million in Monero and imposed a 24-hour deadline, escalating an incident that exposed sensitive information belonging to hundreds of the fintech company’s customers.
The group, calling itself “iamnotavillain,” published the ultimatum on a website alongside a countdown clock on September 16, according to the Financial Times. The attackers threatened to sell the information to other criminal groups unless Revolut pays roughly 6,000 XMR, the privacy-focused cryptocurrency Monero.
Revolut, however, told Reuters that it had received no direct contact or ransom demand from the people claiming responsibility. The attackers also told the Financial Times that negotiations with Revolut had not taken place.
That distinction means the $3 million demand remains a public claim by the threat actor rather than evidence of an active ransom negotiation.
The breach is understood to affect about 680 customers. Revolut has said its core infrastructure, databases and customer accounts were not hacked and that customer funds remain unaffected.
Fraudulent Government Requests Exposed Customer Records
The breach originated not from attackers penetrating Revolut’s banking systems but from fraudulent information requests that appeared to come from a legitimate government agency email domain.
Revolut confirmed on September 12 that it disclosed customer information to an unauthorized third party after receiving the requests. The company subsequently blocked the address and notified law enforcement, financial regulators and data-protection authorities.
The attackers claim they compromised an Italian government email system and impersonated law-enforcement officials while requesting customer records over several months. The Financial Times reported that the group provided evidence appearing to support parts of that account, although authorities have not publicly verified all of its claims.
Information exposed in the incident reportedly includes passports and driving licences, identity-verification photographs, addresses, contact information, bank details, account statements and transaction histories.
The attackers said they specifically targeted customers holding significant cryptocurrency positions, using blockchain analysis to identify potential “crypto whales.” Most affected customers were reportedly based in Switzerland and France, with others spread across more than 30 European countries.
Monero Demand Adds Privacy Dimension
The choice of Monero is notable because its blockchain is designed to obscure transaction information that is publicly visible on networks such as Bitcoin.
The new demand also differs dramatically from an earlier claim circulating online that sought 10,000 Bitcoin, worth hundreds of millions of dollars. The iamnotavillain group disputes that demand and says another party given access to a sample of the information falsely claimed responsibility for the broader breach. Neither ransom figure has been independently validated by Revolut.
The incident is already attracting regulatory scrutiny. Britain’s Information Commissioner’s Office has received a report and is assessing the breach, while the Financial Conduct Authority is engaging with Revolut.
For affected customers, the risk extends beyond conventional financial fraud. Identity documents combined with addresses and detailed cryptocurrency transaction histories could potentially facilitate targeted phishing, account-recovery attacks or physical extortion attempts against people believed to control valuable digital assets.
Revolut says affected customers have been contacted directly and are receiving support.
The immediate question is therefore not whether Revolut’s banking infrastructure was compromised — the company says it was not — but what happens to the customer information already obtained. With the attackers’ 24-hour ultimatum, the incident has moved from a data-security failure into an active extortion threat.
