Back 247wallst.com Hackers Want 3 Million In Monero For Revoluts Stolen Bitcoin Records What Affected Customers Should Do Now
Attackers posed as Italian law enforcement for months, convincing Revolut to hand over passports, selfies, and full transaction histories on hundreds of high-net-worth crypto holders. Here is what those customers face now and what the stolen files actually allow someone…
This post may contain links from our sponsors and affiliates, and Flywheel Publishing may receive compensation for actions taken through them.
A group that goes by the name iamnotavillain spent months emailing Revolut from an Italian government domain, posing as law enforcement and requesting files on named customers. The requests cleared Revolut’s verification, and the fintech handed over passports, the selfies customers submit for identity checks, addresses, account details and full transaction histories.
Revolut confirmed the disclosure on September 12, 2026 , and notified affected customers the same day. On September 16, the group published a demand for 6,000 Monero ( CRYPTO:XMR ), worth roughly $3 million, with a 24-hour countdown. Revolut says it has received no direct ransom demand, which leaves the 680 people named in those files waiting on a negotiation neither side has opened.
How the Attackers Obtained the Records
The attackers first engaged in reconnaissance. They told the Financial Times they used blockchain analysis to pinpoint Revolut accounts with substantial amounts of cryptocurrency, allowing them to identify the customers they wanted to target before sending any emails. Blockchain investigator ZachXBT noted that the targets were high-net-worth individuals instead of a random mix of users.
came the fraudulent paperwork. The attackers created an email account using the domain of a legitimate Italian government agency, reportedly connected to the Ministry of the Interior, and submitted law enforcement information requests over several months.
Italian authorities are currently investigating how this unauthorized use of the government’s certified email system occurred. At least 680 customers across 31 countries had their files compromised.
Revolut maintains that its core systems, databases, and customer funds remain untouched, which is accurate. However, this offers little reassurance to customers. The protocols Revolut has in place for handling police requests functioned as designed, and the attackers presented themselves convincingly enough as Italian law enforcement to evade suspicion, as the number of requests did not trigger any alarms.
Why the Ransom Is Demanded in Monero
Bitcoin ( CRYPTO:BTC ) records all transactions on a public ledger, allowing any wallet receiving ransom payments to be tracked and blacklisted by exchanges. Companies that specialize in chain analysis monitor these transactions, enabling investigators to freeze proceeds as soon as the coins reach a regulated venue.
In contrast, Monero is designed to evade such tracking . Its protocol generates a unique temporary address for each transaction and conceals the sender, receiver, and amount, preventing a public balance from accumulating and being tracked. This makes Monero a popular choice for extortion demands.
However, the shift to Monero is not as straightforward as it might seem. Initially, a demand for 10,000 Bitcoin, approximately $780 million, circulated under the name Revolut Smilik. Iamnotavillain claims that an impersonator who received a data sample is wrongfully taking credit for the broader breach. Until Revolut or a regulatory authority confirms otherwise, both figures reflect the attackers’ claims, while only the company’s data disclosure is a factual event.
What the Stolen Files Can and Cannot Do
Certain sensitive information was protected from disclosure. Revolut has verified that the released data did not include cryptographic private keys, account passwords, security authentication codes, or full payment card details. A passport scan cannot facilitate cryptocurrency transactions, and the files do not contain keys that could unlock digital wallets.
However, the files do include a passport, a matching verification selfie, an address, an IBAN, and a complete transaction history, including cryptocurrency activity. This combination can be used to pass identity checks at other banks or exchanges, potentially opening accounts in someone else’s name and revealing the venues a person uses and their approximate holdings.
Because the 680 accounts were selected based on the size of their holdings, the risk targets specific individuals rather than the general population.
The threat has already emerged, with individuals in the cryptocurrency industry facing personal blackmail using the stolen identity documents and transaction records. Customers who ignored notifications and made no changes are now receiving these extortion messages, particularly those still relying on a password and an SMS code rather than more secure measures like a hardware key or a withdrawal whitelist.
Revolut has notified law enforcement, alerted the relevant government agency whose domain was misused, and blocked the fraudulent email channel. UK regulators are currently reviewing the situation, which arrives shortly after the company secured conditional approval to operate as a national bank.
Is Paying Ever the Answer Here?
The decision was never the customers’ to make. Revolut says it has received no direct demand, and the group published its ultimatum on a website rather than sending it to the company, which reads as pressure staged for the press rather than an opening negotiation. The group also claims to hold 147 gigabytes of data and to have reached Italian law enforcement systems, and Italian authorities have confirmed neither.
For the 680 people named in those files, the cost is already paid and cannot be refunded. The documents are out, and the only open question is who buys them and what they do with such a precise list. A fix at Revolut alone will not close this, because every bank and exchange handling law enforcement requests runs the same process, and a group that got past one will try the .
[email protected] for any questions or corrections.
Sam Daodu is a crypto analyst who's spent nearly a decade making blockchain understandable—no easy task when most whitepapers read like fever dreams. He writes for 24/7 Wall St., covering Bitcoin, altcoins, and crypto market analysis for investors. Before crypto, he was a tech writer (back when explaining "the cloud" was peak innovation). Since 2018, he's written for CoinTelegraph, Yahoo Finance, The Block, Cryptonews, Zypto, Rain, and more—basically anywhere people want crypto news without the headache. Sam runs MacLabs Marketing, a content agency for crypto brands tired of sounding like AI wrote their website. He also publishes free crypto education on his site for Web3 enthusiasts who think "gas fees" is a typo. When he's not writing or staring at charts, Sam's either: - Watching anime (currently convinced One Piece has better tokenomics than most altcoins) - At the gym sculpting himself into a Greek god - Listening to the music your mum warned you only bad boys listen to Connect: | Email | MacLabs Marketing
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
