$3 M in XMR or Customer Data for Sale? The Threat from Revolut Hackers
2026-09-17
Reports that Revolut hackers demand $3 million in XMR have raised concerns about customer privacy, crypto-related targeting, and the possible sale of sensitive financial data. A group calling itself “iamnotavillain” reportedly threatened to release or sell information obtained through fraudulent government data requests unless Revolut paid 6,000 Monero.
Revolut confirmed an unauthorized disclosure affecting a limited number of customers but said its internal systems and customer funds were not compromised. Several details, including the hackers’ identity, victim count, targeting methods, and access claims, remain unverified or based primarily on the group’s statements.
Key Takeaways
- A group claiming responsibility for the Revolut breach reportedly demanded 6,000 XMR, worth approximately $3 million when the demand was issued, and threatened to sell the customer data.
- Revolut confirmed that fraudulent requests sent through a legitimate government agency email domain caused an unauthorized disclosure, but said its systems and customer funds were unaffected.
- Customers should treat messages containing accurate personal or transaction information as potentially fraudulent and verify every request through Revolut’s official application.
What Is the Revolut Hackers’ $3 Million XMR Threat?

(image source: instagram.com)
The Revolut hackers’ threat is a reported extortion attempt involving customer information obtained through fraudulent government data requests. According to the Financial Times, the group “iamnotavillain” published a demand for 6,000 XMR, described at the time as approximately $3 million, and gave Revolut 24 hours to pay.
The group reportedly threatened to sell the information to other criminal organizations if payment was not made. However, Revolut told Reuters that it had received no direct contact or ransom demand from the alleged attackers.
This distinction matters. The ransom demand was publicly reported and attributed to the group, but the available evidence does not establish that Revolut entered negotiations or recognized the demand as authentic.
What Has Revolut Confirmed?
Revolut confirmed that an unauthorized third party obtained sensitive customer information by submitting fraudulent information requests through a legitimate government agency email domain. The company described the incident as a sophisticated external impersonation scam rather than a direct intrusion into Revolut’s core infrastructure.
Revolut said it took several actions after identifying the activity:
- Blocked the email address associated with the fraudulent requests
- Contacted the customers it identified as affected
- Alerted the relevant government agency
- Notified law enforcement and applicable regulators
- Began reviewing and strengthening its information-request procedures
Revolut has stated that its internal systems and customer funds were unaffected. There was no confirmed compromise of customer passwords, private keys, card balances, or the underlying cryptocurrency networks.
Readers seeking background on the original disclosure can review the earlier Bitrue analysis of the Revolut data breach and exposed KYC records.
What Is Confirmed and What Remains Alleged?
Several important details come from the alleged hackers rather than Revolut or an investigating authority. They should not be presented with the same certainty as Revolut’s confirmed disclosure.
The available reporting supports the existence of a real unauthorized disclosure. It does not independently verify every claim made by “iamnotavillain,” including the full quantity of data, the group’s access method, or whether all displayed records were authentic.
How Did the Revolut Data Breach Happen?

(image source: corksafetyalerts.com)
The incident reportedly exploited a trusted information-sharing process instead of directly hacking Revolut’s banking platform. Fraudulent requests appeared to originate from a legitimate government communication channel, causing customer records to be released to an unauthorized party.
The alleged attackers told the Financial Times that they had gained access to an Italian government email system and used it to impersonate law enforcement. They claimed to have submitted repeated requests over several months, but these operational details have not been independently confirmed by Revolut or Italian authorities.
This attack method highlights an important security distinction. Verifying that an email comes from a recognized domain does not necessarily prove that the sender is authorized, that the account has not been compromised, or that the request itself is legitimate.
Strong verification for sensitive data requests can require independent confirmation through a separate channel, validation of case identifiers, approval by multiple employees, and scrutiny of unusual request patterns.
What Customer Data May Have Been Exposed?
Notices reviewed by news organizations indicate that the disclosed information could include personal identity, contact, account, and transaction records. The exact information may differ between affected customers.
Reported data categories include:
- Names and dates of birth
- Postal and email addresses
- Phone numbers
- Passports and driving licences
- Identity-verification photographs or selfies
- Account statements
- Payment and transaction histories
- Cryptocurrency transaction information
The Financial Times reportedly received a short screen recording that appeared to show identity documents, KYC photographs, and transaction histories. A recording can support a group’s claim, but it does not independently establish the complete size, accuracy, or current possession of the dataset.
Revolut has referred to a limited number of affected customers without publicly confirming an exact figure. Reports that at least 680 accounts were affected should therefore be treated as a reported estimate rather than a company-confirmed total.
Readers can monitor the latest XMR market data on Bitrue to understand how Monero’s price responds to market and security developments.
Why Did the Hackers Demand Payment in Monero?
The alleged attackers requested Monero because XMR is designed to provide stronger transaction privacy than transparent-blockchain assets such as Bitcoin. Monero uses technologies including stealth addresses, ring signatures, and Ring Confidential Transactions to conceal transaction participants and amounts.
These privacy features can make financial tracing more difficult, which is one reason XMR sometimes appears in extortion demands. The use of Monero in an alleged crime does not mean the Monero network was hacked, involved in the data breach, or responsible for the attackers’ conduct.
The 6,000 XMR demand was described as being worth approximately $3 million when reported. Its dollar value can change because XMR remains a volatile crypto asset.
Were Crypto Users Specifically Targeted?
The alleged hackers claimed that they used blockchain analysis to identify Revolut customers with significant cryptocurrency holdings. This claim has been widely reported, but it has not been independently verified.
The group reportedly described its targets as high-value crypto users. It is not publicly established that every affected customer owned large crypto balances or that blockchain analysis was the only selection method.
Nevertheless, combining KYC records with cryptocurrency transaction histories creates serious privacy concerns. Public blockchain data is usually pseudonymous, but information from a centralized financial institution can potentially connect wallet activity with a real person, contact details, identity documents, and account history.
This combination can make exposed customers more vulnerable to:
- Highly personalized phishing messages
- Fraudulent account-recovery attempts
- Identity theft and document misuse
- SIM-swapping or mobile account attacks
- Impersonation of banks, exchanges, or government agencies
- Targeted crypto theft or extortion
- Physical-security risks if criminals believe a person controls valuable assets
The exposure of transaction information does not give an attacker automatic access to a crypto wallet. Private keys, seed phrases, passwords, and authentication codes are still required to authorize transactions from independently controlled wallets.
Did the Attackers Steal Customer Funds?
There is currently no confirmed evidence that the incident directly resulted in stolen customer balances. Revolut has said that its systems and customer funds were unaffected.
A data breach can still create financial danger after the initial incident. Criminals may use exposed personal information to build convincing messages, impersonate support agents, or manipulate account-recovery processes.
Customers should not assume that a caller is legitimate merely because the caller knows their address, recent transaction, identity-document details, or account activity. Such information may be the result of a breach rather than proof that the caller represents Revolut or another financial institution.
Read Also: Monero Reaches New All-Time Highs Amid Rising Privacy Regulation Fears
What Should Revolut Customers Do Now?
Affected customers should focus on preventing secondary fraud and unauthorized account access. These steps are also relevant to users who have not received a breach notification but are concerned about targeted scams.
- Confirm whether Revolut contacted you. Check notifications inside the official Revolut application rather than following links in an unexpected email or text message.
- Review recent account activity. Examine card payments, transfers, linked devices, login sessions, and cryptocurrency transactions for anything unfamiliar.
- Strengthen account security. Use a unique device passcode, secure the associated email account, enable available authentication protections, and update reused passwords.
- Reject unsolicited security requests. Never disclose passwords, one-time codes, card details, seed phrases, private keys, or recovery information to an unexpected caller or message sender.
- Verify communications independently. Contact Revolut through its official in-app support channel if someone claims that your account, funds, or identity documents are at risk.
- Protect related crypto accounts. Review exchange security, withdrawal allowlists, API keys, wallet permissions, and email access, particularly if exposed records could connect your identity to crypto holdings.
- Watch for identity misuse. Monitor financial accounts and credit information where suitable services are available in your country, and report suspected identity fraud to the relevant institutions or authorities.
Users should avoid responding to the alleged hackers or attempting to locate, purchase, or download leaked records. Doing so could expose the user to malware, fraud, or legal risk.
What Does the Incident Mean for Financial Platforms?
The incident demonstrates that cybersecurity extends beyond firewalls, passwords, and software vulnerabilities. A financial institution can maintain secure internal systems while attackers target the legal, compliance, and information-sharing processes surrounding those systems.
Government and law-enforcement requests often require financial companies to disclose customer records under valid legal authority. Criminals who compromise or convincingly imitate those channels may attempt to exploit the trust attached to official communications.
Financial platforms can reduce this risk by requiring independent verification, limiting employee access to customer records, applying multiple approvals, monitoring repeated requests, and rapidly sharing warnings when government accounts are suspected of being compromised.
What Remains Unknown?
Several central questions remained unresolved when the threat was reported:
- Whether “iamnotavillain” possesses all the data it claims
- The final number and geographic distribution of affected customers
- Whether the group compromised an Italian government account or used another impersonation method
- Whether any customer information has already been sold or distributed
- Whether other financial institutions received similar fraudulent requests
- Whether the reported 24-hour deadline led to further contact or action
- Whether regulators or law enforcement have identified the individuals responsible
New statements from Revolut, regulators, law enforcement, or the relevant government agency could materially change the available assessment. Those researching the privacy coin can review available methods for purchasing Monero through Bitrue before comparing access options, costs, and risks.
Conclusion
The Revolut hackers’ threat is serious because identity documents, transaction histories, and contact information could support targeted fraud even when customer funds were not directly stolen.
Revolut has confirmed an unauthorized disclosure through fraudulent government requests but has not publicly validated the alleged hackers’ full account of the incident. The $3 million XMR demand, the reported 680 affected accounts, and the claimed targeting of crypto holders should remain clearly attributed to news reports and the group’s own statements.
Customers should monitor official updates, secure related accounts, and treat highly personalized messages with caution. Readers can explore crypto markets through Bitrue Exchange, while additional security updates and cryptocurrency education are available on the Bitrue Blog.
FAQ
Did Revolut hackers demand $3 million in XMR?
A group calling itself “iamnotavillain” reportedly demanded 6,000 XMR, valued at approximately $3 million when the demand was published. Revolut told Reuters that it had not received a direct ransom demand or communication from the alleged attackers.
How many Revolut customers were affected?
The Financial Times reported that at least 680 customer accounts were affected, but Revolut has not publicly confirmed that number. The company has described the affected group as limited and said it contacted identified customers directly.
Was Revolut’s banking system hacked?
Revolut said its internal systems were not compromised. The confirmed incident involved fraudulent information requests sent through a legitimate government agency email domain, which resulted in customer data being disclosed to an unauthorized party.
Why did the hackers request Monero instead of Bitcoin?
Monero conceals transaction participants and amounts by default, making transfers more difficult to analyze than transactions on transparent blockchains. Requesting XMR does not indicate that Monero itself was compromised or participated in the incident.
What should an affected Revolut customer do?
Affected customers should review account activity, secure their email and financial accounts, and verify communications through Revolut’s official in-app support. They should never share passwords, private keys, seed phrases, or authentication codes in response to unsolicited messages.
Disclaimer: The views expressed belong exclusively to the author and do not reflect the views of this platform. This platform and its affiliates disclaim any responsibility for the accuracy or suitability of the information provided. It is for informational purposes only and not intended as financial or investment advice.
Disclaimer: The content of this article does not constitute financial or investment advice.




