Close Menu

    Subscribe to Updates

    What's Hot

    UK crypto firms face fresh FCA authorization process

    September 16, 2026

    The Devcon schedule is live!

    September 16, 2026

    Revolut hackers demand $3M in Monero after data breach

    September 16, 2026
    Facebook X (Twitter) Instagram
    laicryptolaicrypto
    Demo
    • Ethereum
    • Crypto
    • Altcoins
    • Blockchain
    • Bitcoin
    • Lithosphere News Releases
    laicryptolaicrypto
    Home Revolut hackers demand $3M in Monero after data breach
    Crypto

    Revolut hackers demand $3M in Monero after data breach

    John SmithBy John SmithSeptember 16, 2026No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Hackers behind the Revolut customer data breach have demanded 6,000 Monero, worth about $3 million, while threatening to sell the stolen records unless the bank pays within 24 hours.

    Summary

    • Hackers have demanded 6,000 XMR, valued at about $3 million, from Revolut.
    • At least 680 customer accounts were affected after fraudulent government requests passed company checks.
    • Stolen records reportedly include identity documents, verification photos and complete transaction histories.
    • The attackers said blockchain analysis helped them identify customers with large crypto holdings.

    How Revolut hackers set the 24-hour deadline

    The Financial Times reported that a group calling itself “iamnotavillain” published the ransom demand on Wednesday alongside a countdown clock. The hackers said Revolut had 24 hours to send 6,000 XMR before they offered the customer records to other criminal groups.

    At an implied value of about $500 per token, the demand totals approximately $3 million. The group selected Monero because the cryptocurrency is designed to conceal information about the sender, recipient and amount involved in a transaction.

    According to the FT, no negotiations between Revolut and the hackers had taken place by the time its report was published. Revolut had not said whether it planned to respond to the demand or confirmed that the group controlled the stolen information.

    The hackers provided the newspaper with a 60-second screen recording that appeared to display part of the material in their possession. Passports, driving licences, photographs submitted during know-your-customer checks and customer transaction histories appeared in the video, according to the report.

    At least 680 accounts were affected, although Revolut has publicly described the number only as a “very limited” portion of its customer base. A previous crypto.news report found that Britain’s Information Commissioner’s Office had opened an investigation after the company reported the incident to regulators.

    Revolut has said its own systems and customer funds were not compromised. Instead, the disclosure occurred after the company received fraudulent requests through an email account using the domain of a legitimate government agency.

    Fake government requests exposed Revolut customer records

    Rather than breaking directly into Revolut’s infrastructure, the attackers posed as government officials seeking customer information. The requests carried valid domain-authentication credentials and passed the checks Revolut used to assess their legitimacy.

    Revolut then supplied customer records before discovering that the requests were fraudulent. Once the scheme was identified, the company said it blocked the email address and contacted the government agency, law enforcement, data-protection authorities and financial regulators.

    As initial coverage detailed, the information released included full names, dates of birth, occupations, home addresses, email addresses and telephone numbers. Copies of passports or driving licences and selfies provided for identity verification were also among the listed records.

    Account data included International Bank Account Numbers, account-opening dates, account status, withdrawal records and complete transaction histories. Bitcoin wallet reference numbers and records of Bitcoin transactions were also contained in some account statements.

    Revolut’s customer notice distinguished identity-check photographs from biometric facial telemetry data, which the company said was not part of the disclosure. The notice also did not identify private keys, passwords, security codes or complete payment-card details among the exposed information.

    An earlier company statement described the incident as a “sophisticated external impersonation scam” and maintained that Revolut’s systems remained secure. The company has not publicly identified the government agency whose email domain was used or explained how the attackers gained access to an account operating through that domain.

    Blockchain analysis reportedly identified crypto-rich targets

    The hackers told the FT that they used blockchain analysis to select Revolut customers who appeared to hold substantial amounts of cryptocurrency. Their account, if accurate, would indicate that the affected group was chosen partly through its financial activity rather than through a random collection of customer profiles.

    On-chain investigator ZachXBT had previously said the incident appeared to involve high-net-worth users, though Revolut had not confirmed that assessment. The hackers’ latest statement provides a similar account of their targeting method, but it has not been independently verified.

    Public blockchains can expose transaction histories, wallet balances and transfers between addresses. Analysts can sometimes connect that activity with an identified person when an exchange, financial company or other service holds records linking a customer account to a blockchain address.

    The disclosed Revolut records may contain both sides of that connection. Identity documents and contact information can identify the account holder, while Bitcoin transaction histories and wallet reference numbers can map parts of the person’s crypto activity.

    An August review of privacy coins explained that Monero makes transaction privacy mandatory. Its ring signatures obscure the true sender among a group of possible participants, stealth addresses hide the recipient’s public address, and Ring Confidential Transactions conceal the amount sent.

    Criminal use of XMR does not establish that the token or all of its users are engaged in illegal activity. Monero also serves people seeking financial privacy, but its design can make illicit payment trails more difficult for investigators to follow than activity conducted on transparent networks such as Bitcoin or Ethereum.

    A separate August case showed the same challenge after investigators said assets from a reported $7.9 million Coinsbuy hack were converted into Monero. Blockchain firms tracked portions of those funds through several exchanges before some assets were reportedly exchanged for XMR.

    What the breach means for U.S. crypto customers

    The FT report did not specify whether any of the 680 affected accounts belonged to U.S. customers. Still, the combination of verified identity records and crypto transaction data creates a relevant risk for Americans who receive messages claiming to come from Revolut, an exchange, a government agency, or a wallet provider.

    Such records could allow criminals to craft messages containing a real name, transaction, account detail, or identity document. The presence of accurate personal information does not prove that a caller or sender represents the bank.

    Revolut’s U.S. security guidance says the company will not unexpectedly call customers and ask them to make a payment or disclose verification and security codes. Customers who receive suspicious contact can verify it through the company’s in-app support channel.

    For Americans whose personal or banking information has been exposed, the Federal Trade Commission directs consumers to IdentityTheft.gov for steps based on the type of data involved. The agency also advises users to report phishing attempts through ReportFraud.ftc.gov.

    The FBI’s Internet Crime Complaint Center asks people reporting cryptocurrency-related fraud to provide wallet addresses, transaction amounts, asset types, transaction hashes, and the dates and times of transfers when available.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    John Smith

    Related Posts

    UK crypto firms face fresh FCA authorization process

    September 16, 2026

    CLARITY Act failure shifts US crypto rules to agencies: experts

    September 16, 2026

    Ondo becomes first tokenization firm on DTCC Fund/SERV

    September 16, 2026
    Leave A Reply Cancel Reply

    Demo
    Don't Miss
    Crypto

    UK crypto firms face fresh FCA authorization process

    By John SmithSeptember 16, 20260

    The UK Financial Conduct Authority has issued final guidance requiring crypto firms to reassess their…

    The Devcon schedule is live!

    September 16, 2026

    Revolut hackers demand $3M in Monero after data breach

    September 16, 2026

    Mekong Testnet Announcement | Ethereum Foundation Blog

    September 16, 2026

    LAI Crypto is a user-friendly platform that empowers individuals to navigate the world of cryptocurrency trading and investment with ease and confidence.

    Our Posts
    • Altcoins (22)
    • Bitcoin (11)
    • Blockchain (15)
    • Crypto (719)
    • Ethereum (453)

    Subscribe to Updates

    • Twitter
    • Instagram
    • YouTube
    • LinkedIn

    Type above and press Enter to search. Press Esc to cancel.