Revolut hackers demand 6,000 XMR ransom after customer data breach
Hackers claiming responsibility for a Revolut data breach have demanded 6,000 XMR, worth about $3 million, within 24 hours. The group, calling itself iamnotavillain, threatened to sell confidential records from about 680 customers to other criminal groups if Revolut does not pay. The ultimatum appeared online alongside a countdown clock.
The breach involved fraudulent requests sent through a legitimate government email domain. Attackers allegedly posed as law enforcement and obtained customer information over several months. Potentially exposed records include identity documents, account details and transaction histories, including Bitcoin activity. The attackers said blockchain analysis helped them identify customers with significant cryptocurrency holdings.
However, Revolut says it has not received a direct ransom demand from the alleged attackers. The company has said its core systems, databases and customer accounts were not hacked. Regulators and law enforcement are investigating the incident, while affected customers have been contacted. The case highlights how trusted government communication channels can become an entry point for targeted financial-data theft.
Why it matters
The incident raises cybersecurity risks for fintech and crypto users, especially customers whose transaction histories may expose their holdings.


