News View Non-AMP

Revolut Hackers Demand $3M in XMR, Give 24 Hours to Pay

Published by
Rizwan Ansari

Hackers claiming responsibility for a Revolut data breach are demanding a $3 million ransom in Monero (XMR) and have given the fintech firm 24 hours to pay. The group says it will sell the stolen customer data to other criminals if Revolut refuses to pay.

Meanwhile, the Revolut team stated that the company had never received a direct extortion demand from the cybercriminals.

Hackers Gave Revolut 24-Hour Deadline

The group, calling itself “iamnotavillain,” posted the ransom demand, asking Revolut to pay 6,000 XMR, worth around $3 million. The hackers reportedly set a 24-hour deadline and threatened to sell the information if the payment is not made.

“The blood will be on Revolut’s hands.”

The hackers sent the FT a 60 second recording that appeared to show some of the stolen information. The exposed data reportedly includes passports, driving licences, KYC photos and transaction histories, including crypto transaction records. 

Even the former Mt. Gox CEO Mark Karpeles has also said he was among customers notified about the incident.

How Did the Revolut Breach Happen?

The breach did not involve a direct attack on Revolut’s servers. Instead, hackers used fake identities and social engineering to trick the company.

The attackers reportedly accessed an email account linked to an Italian government agency and used it to send fake European Investigation Orders to Revolut. 

Since the requests appeared to come from law enforcement officials, they passed Revolut’s checks. The company then unknowingly shared customer information before finding out that the requests were fake.

At least 680 customer accounts were reportedly affected by the breach. Most of the targeted customers are in Switzerland and France, with others in the UK and Germany.

Response From Revolut Team

Revolut said it has not negotiated with the hackers and has not paid any ransom. The company also said it never received a direct ransom demand from the attackers.

The $3 million Monero (XMR) demand and 24-hour deadline were posted publicly on a new website by the hacker group. The group said that it chose to publish the threat online instead of contacting Revolut directly.

This means there have been no ransom talks between the hackers and Revolut. 

The company is instead focused on containing the incident, working with law enforcement and supporting affected customers.

Rizwan Ansari

Rizwan is an experienced Crypto journalist with almost half a decade of experience covering everything related to the growing crypto industry — from price analysis to blockchain disruption. During this period, he’s authored more than 3,000 news articles for Coinpedia News.

Recent Posts

Zcash Price Rally Accelerates Past $1,300 as Whale Activity Adds to Market Momentum

Zcash price has surged beyond $1,300, extending one of the market’s sharpest rallies as renewed…

September 17, 2026

Ethereum Price Prediction: ETH Holds $2,400 as Analyst Forecasts $10,000 by End of Year

This Ethereum price prediction starts with the tape. Ethereum (ETH) trades at $2,476 on September…

September 17, 2026

Chainlink and Litecoin Slip, But This Presale Token Is Eyeing 20x Gains by October

Chainlink and Litecoin are slipping again, and the whole market is changing direction quickly. Both…

September 17, 2026

CLARITY Act Update After Failure: SEC Chair Breaks Silence, Says ‘Stay Tuned’

SEC Chairman Paul Atkins thanked everyone involved in pushing the CLARITY Act forward, across the…

September 17, 2026

Hyperliquid Perps to Enter US Market via Kraken; HYPE Up 1.7%

In the future, Americans will be able to trade Hyperliquid (HYPE) on-chain perpetual futures through…

September 17, 2026

US Bitcoin Reserve Bill Advances, but Odds of 2027 Law Drop to 6%

The US House Financial Services Committee has voted to advance the unprecedented Strategic Bitcoin Reserve,…

September 17, 2026