Revolut targeted in data breach; hackers demand $3 million in Monero
IN SHORTRevolut is facing a ransom demand of 6,000 Monero, approximately $3 million, from a group claiming to have stolen data from 680 customer accounts. The attackers used fraudulent data requests via a compromised Italian government email domain. Revolut stated that funds, passwords, private keys, and full card details were not compromised, and its systems remain operational.
Key Numbers
6,000Monero (XMR) demanded in ransom
3 millionUS dollars equivalent of ransom demand
680customer accounts allegedly compromised
Who's Involved
iamnotavillain
hacker group demanding ransom from Revolut
Revolut
financial technology company targeted in data breach
The Financial Times
publication that first reported the ultimatum
↳ Why This Matters
The data breach and ransom demand pose a compliance and reputational risk for Revolut, potentially impacting its pending US bank charter approvals and its image as a regulation-first operator. The exploitation of a law-enforcement request pipeline raises concerns about the company's security controls.
Key facts
- Revolut is facing a ransom demand of 6,000 Monero (XMR) from a hacker group.
- The group claims to have stolen data from 680 customer accounts.
- The stolen data includes passports, driving licenses, KYC selfies, IBANs, account statements, and Bitcoin transaction histories.
- Revolut stated that funds, passwords, private keys, and full card details were not compromised.
- Attackers used fraudulent data requests through a compromised Italian government email domain.
A hacker group identifying as 'iamnotavillain' has issued a ransom demand to the financial technology company Revolut, seeking 6,000 Monero (XMR), valued at approximately $3 million. The group claims to have obtained sensitive data from around 680 customer accounts, including passports, driving licenses, KYC selfies, IBANs, account statements, and Bitcoin transaction histories. The ultimatum, reported by The Financial Times on September 16, 2026, states that the stolen data will be sold to other criminal organizations if the ransom is not paid within 24 hours.
Revolut has stated that no customer funds, passwords, private keys, or full card details were compromised, and its operational systems remain intact. The attackers reportedly did not breach Revolut's core systems but instead exploited a compromised Italian government email domain to submit fraudulent data requests. This method mirrors a similar attack on payment processor Transak in 2024, highlighting the vulnerability of KYC vendor workflows. The group claims to have identified the targeted accounts through on-chain analysis of Revolut's heaviest crypto users, a tactic also seen in a previous breach at Coinbase.
The choice of Monero as the ransom currency is deliberate, leveraging its privacy features to obscure the transaction trail. This strategy follows a pattern observed earlier this year where stolen Bitcoin was immediately converted to Monero to evade chain-analysis tools. While Revolut asserts that private keys were untouched, the exposed personal documents pose a risk of physical exposure for the affected users. The incident occurs at a sensitive time for Revolut, which is pursuing a US national bank charter and has been building its compliance credibility in Europe.