Revolut breach: hackers demand $3 million in Monero, threaten to sell data

Hackers who stole data from 680 Revolut users demand 6,000 XMR and threaten to sell the information, exposing risks of social‑engineer attacks and privacy‑focused crypto.

Revolut breach: hackers demand $3 million in Monero, threaten to sell data

According to CoinDesk, a group calling itself “iamnotavillain” posted a 24‑hour deadline demanding 6,000 XMR – roughly $3 million – from Revolut. The hackers warned they would auction the stolen customer data to other criminal outfits if the payment is not made. The breach affected at least 680 accounts and was triggered by fraudulent government‑official requests that slipped past Revolut’s verification steps.

What happened

The attackers posed as government officials and emailed Revolut employees with requests for personal information. The emails passed Revolut’s internal checks, prompting the company to hand over passports, driver’s licences, facial photos used for know‑your‑customer (KYC) verification, and transaction histories. After compiling the data, the group released a 60‑second screen recording showing snippets of the information and attached a countdown clock demanding the Monero payment. They also claimed to have used blockchain analysis to cherry‑pick accounts holding sizable crypto balances, suggesting a focus on high‑value victims.

Why it works that way

Monero (XMR) is a privacy‑oriented cryptocurrency. Unlike Bitcoin, which records every transaction on a public ledger, Monero hides the sender, receiver, and amount through a combination of stealth addresses, ring signatures, and confidential transactions. These technical tricks make it extremely hard for law‑enforcement or blockchain analysts to trace funds once they are moved. For extortionists, that anonymity is the primary selling point: the victim can pay without leaving a paper trail, and the ransom can be laundered across multiple hops before the trail disappears.

The attackers’ first move – social engineering – exploits the trust embedded in KYC processes. Financial institutions are required to verify identity documents, but those checks often rely on manual review of submitted files. By mimicking an official request, the hackers triggered a legitimate compliance workflow, allowing them to extract sensitive records without raising suspicion. After the breach, they used blockchain analytics to identify Revolut users with significant crypto holdings. This step is straightforward: public blockchain data reveals wallet balances, and many exchanges link wallet addresses to user accounts. By cross‑referencing known wallet addresses with Revolut‑provided KYC data, the group could prioritize victims who could afford a multi‑thousand‑dollar ransom.

What changes because of it

Revolut says its core systems and customer funds remain untouched, and it blocked the malicious IP address, notifying regulators and law‑enforcement. For customers, the immediate risk is exposure of identity documents and transaction history, which can be leveraged for identity theft, account takeover, or further phishing campaigns. The threat of a data sale adds a second layer: even if Revolut refuses to pay, the stolen files could appear on dark‑web markets, making the breach a long‑term liability.

From a broader perspective, the incident highlights two friction points in the crypto‑finance ecosystem. First, KYC processes that rely on manual document exchange are vulnerable to spoofed official requests. Companies may need to harden verification by adding multi‑factor authentication for data‑release requests, digital signatures from recognized government portals, or real‑time cross‑checks with official databases. Second, the choice of Monero underscores the growing appetite for privacy coins among cyber‑crime groups. Regulators have already flagged Monero as a high‑risk asset for money‑laundering, and this episode may accelerate discussions about mandatory reporting of large Monero transactions or tighter AML (anti‑money‑laundering) controls on privacy‑focused blockchains.

What we would watch is whether Revolut negotiates, pays, or simply reports the demand to authorities. A payment could set a precedent that encourages similar ransomware‑style extortion against other fintech firms, especially those holding customer crypto assets. Conversely, a refusal coupled with swift law‑enforcement action could deter future attackers, but only if the stolen data does not end up for sale. Customers should monitor their credit reports, consider identity‑theft protection services, and review any linked crypto wallets for unauthorized activity. For the industry, the episode is a reminder that protecting data is as crucial as safeguarding funds; a breach that exposes personal documents can be just as damaging as a loss of crypto.

Sources

related

We count page views without cookies — no identifier, nothing stored on your device. Accept to allow cookies for analytics.