Roobet Banner
BTC $85,220.00 (+5.83%)
ETH $2,736.84 (+5.99%)
BNB $789.78 (+4.95%)
XRP $1.49 (+7.74%)
SOL $116.89 (+7.83%)
TRX $0.34 (+0.51%)
ZEC $1,540.23 (+5.75%)
HYPE $95.28 (+4.44%)
DOGE $0.09 (+10.28%)
XMR $572.37 (+7.58%)
RAIN $0.01 (+6.74%)
LINK $13.12 (+8.39%)
ADA $0.25 (+10.43%)
LEO $8.94 (+0.03%)
XLM $0.21 (+9.72%)
UNI $9.01 (+4.33%)
NEAR $4.19 (+12.21%)
BCH $270.23 (+9.57%)
AVAX $11.39 (+9.43%)
LTC $62.89 (+10.16%)

Hackers Demand $3M in Monero After Breaching 680 Revolut Accounts

Share on X icon · Published 4 дня назад on September 17, 2026 · Hassan Maishera

Hackers are demanding $3 million in Monero after exposing data from at least 680 Revolut accounts, including identity documents and transaction histories.

Hackers Demand $3M in Monero After Breaching 680 Revolut Accounts

TL;DR

  • Revolut hackers are demanding 6,000 XMR, worth approximately $3 million.

  • The group threatened to sell the stolen information if Revolut did not pay within 24 hours.

  • At least 680 customer accounts were reportedly affected.

  • Exposed records may include identity documents, KYC photographs, and transaction histories.

Hackers behind a data breach affecting Revolut customers are demanding about $3 million in Monero, threatening to sell the stolen information to other criminal organizations if the company refuses to pay.

The group, which calls itself “iamnotavillain,” reportedly demanded 6,000 XMR and gave Revolut 24 hours to comply. Its announcement included a countdown clock.

At least 680 customer accounts were affected, although Revolut said its internal systems and customer funds remained secure.

Hackers Demand 6,000 XMR

The attackers selected Monero for the ransom payment, according to the Financial Times.

Monero is a privacy-focused cryptocurrency designed to conceal transaction information, including wallet addresses and transferred amounts. 

These characteristics have made XMR more difficult to trace than transactions on transparent blockchains such as Bitcoin or Ethereum.

The hackers said there had been no negotiations with Revolut at the time of publication. It remains unclear whether Revolut intends to pay the ransom. 

Security authorities generally warn that paying extortion demands does not guarantee that criminals will delete stolen information or refrain from selling it.

The group provided the Financial Times with a 60-second screen recording that appeared to demonstrate its access to customer records.

The material reportedly included passports, driving licences, photographs submitted for know-your-customer verification and transaction histories.

Such information could be used for identity theft, account takeover attempts, targeted phishing or fraudulent financial applications.

Affected customers should be particularly cautious about unexpected emails, calls or messages claiming to come from Revolut, government agencies or cryptocurrency services.

Crypto Holders Were Reportedly Targeted

The hackers told the Financial Times that they used blockchain analysis to identify Revolut customers believed to hold significant amounts of cryptocurrency.

Although public blockchains do not usually display legal names directly, transaction patterns and information connected to exchanges or financial accounts can sometimes be used to associate wallet activity with individuals.

The claim suggests the attackers may have targeted specific customers rather than collecting records indiscriminately.

The breach reportedly did not result from attackers penetrating Revolut’s technical systems.

Instead, the hackers allegedly impersonated government officials and submitted fraudulent requests for customer information. The requests passed Revolut’s verification procedures, causing the company to disclose customer records before discovering the deception.

The incident highlights the risk posed by social engineering, where attackers manipulate employees or institutional processes rather than exploiting software vulnerabilities.

Revolut Says Customer Funds Were Unaffected

Revolut previously said it blocked the address used to submit the fraudulent requests.

The company also notified the relevant government agency, law-enforcement authorities and regulators. It said its systems were not compromised and customer funds were unaffected.

However, the exposure of identity documents and financial histories may create continuing risks for affected users even if no money was stolen directly during the breach.

 

Bitcoin Reclaims $85,000 as ETF Inflows Hit $433M
Next article Bitcoin Reclaims $85,000 as ETF Inflows Hit $433M
Hassan Maishera
Hassan Maishera Senior Reporter

Hassan is a Nigeria-based financial content creator that has invested in many different blockchain projects, including Bitcoin, Ether, Stellar Lumens, Cardano, VeChain and Solana. He currently works as a financial markets and cryptocurrency writer and has contributed to a large number of the leading FX, stock and cryptocurrency blogs in the world.