Latest News

Revolut’s 24-Hour Ransom Clock Has Run Out — No Data Sale…

The 24-hour deadline set by hackers extorting Revolut has expired, but there is so far no independent confirmation that the group has followed through on its threat to sell sensitive customer information to other criminals.

A threat actor calling itself “iamnotavillain” publicly demanded 6,000 Monero, worth approximately $3 million, from the fintech this week. The demand appeared alongside a countdown clock and warned that information obtained on at least 680 customers would be sold if payment was not made within 24 hours.

That countdown expired on September 17. As of September 18, no reliable source has independently verified that the customer database has subsequently been sold or that Revolut paid the ransom. Revolut has also said it received no direct ransom demand or communication from the group, making the unusually public extortion campaign different from a conventional private ransomware negotiation.

What Happens After the Deadline?

The expiration leaves the incident in an uncertain phase.

The hackers threatened to sell information including identity documents, addresses and transaction histories to other criminal groups. The Financial Times reported that the compromised population included approximately 680 customers, many selected because blockchain analysis suggested they held substantial cryptocurrency positions.

The attackers claim they obtained the records by compromising or otherwise exploiting an Italian government email system and then impersonating law-enforcement authorities when submitting information requests to Revolut. The Financial Times reviewed redacted screenshots appearing to support parts of the group’s account, although the full scope of its claims has not been independently established.

Revolut has confirmed the underlying data incident but describes it as a sophisticated external impersonation attack rather than a compromise of its internal infrastructure.

The company said fraudulent information requests arrived from a legitimate government-agency email domain and passed technical authentication checks. Revolut consequently disclosed customer information before identifying the requests as fraudulent. Its security team subsequently blocked the address and contacted authorities and affected customers. Customer funds and Revolut’s core systems were not compromised, according to the company.

Stolen Data Creates Risks Beyond the Ransom

The significance of the expired deadline extends beyond whether the hackers actually sell the files.

Information exposed in the incident reportedly includes names, dates of birth, addresses, telephone numbers and email addresses alongside passports, driving licences and verification photographs. Some affected records may also contain IBANs, account statements and cryptocurrency transaction histories.

For crypto holders, that combination creates an additional physical-security concern. The Wall Street Journal reported that victims include people with substantial cryptocurrency exposure, raising fears that leaked identity, residential and financial information could facilitate highly targeted fraud, extortion or so-called wrench attacks.

The incident is already attracting regulatory scrutiny. Britain’s Information Commissioner’s Office is investigating, while Revolut says it has informed relevant law-enforcement, data-protection and financial regulators.

The critical unanswered question is now whether iamnotavillain carries out its threat.

The deadline passing does not itself establish that the stolen records have been sold, released or transferred to another criminal organization. Until evidence of such a transaction or a new publication emerges, the confirmed development is narrower: the hackers’ $3 million Monero ultimatum has expired without any publicly confirmed payment — and without confirmation that their threatened next step has occurred.

You may also like