Skip to content
Revolut Hackers Demand $3 Million Ransom After Data Breach Reported

Revolut Hackers Demand $3 Million Ransom After Data Breach Reported

Globalbankingandfinance September 16, 2026

Sept 16 (Reuters) - Revolut has had no direct or demand from the individuals or group claiming responsibility for a data breach, a company spokesperson told Reuters on Wednesday.

Attackers' Ransom Threats and Media Reports

The Financial Times reported that attackers claiming responsibility for a data breach at the company had threatened to sell confidential records of hundreds of customers to other criminal groups unless Revolut paid a $3 million ransom within 24 hours.

Key Details of the Revolut Data Breach

Here are some details:

Revolut's core infrastructure, databases and customer accounts were not hacked, a source familiar with the matter said.

The breach is understood to have affected 680 customers, according to the source.

Identity and Actions of the Attacker Group

The group, which calls itself iamnotavillain, published the ultimatum online on Wednesday afternoon to a digital countdown clock, the FT report said.

The group told the newspaper it was using the website to make its demands for the first time and that there had not been any negotiations with Revolut.

How the Breach Occurred

Revolut said on Saturday that sensitive customer information was disclosed to an unauthorized third party after it received fraudulent requests from a legitimate government agency email domain.

(Reporting by Gnaneshwar Rajan and Preetika Parashuraman in Bengaluru; Editing by Vijay Kishore and Tasim Zahid)

Revolut says attackers (iamnotavillain) have not made any direct or ransom demand to the company, despite publicly posting a $3 million ultimatum to sell data if unpaid within 24 hours ( uk.marketscreener.com ).

The breach did not involve hacking Revolut’s systems; instead, sensitive data of approximately 680 customers—such as passports, ID, details—was disclosed following fraudulent requests made via a spoofed government email domain ( rte.ie ).

Revolut has blocked the fraudulent email source, notified law enforcement and regulators, and directly contacted affected customers, emphasizing that core infrastructure, customer accounts and funds remain secure ( techcrunch.com )

Revolut hackers demand $3 million ransom, FT reports | MarketScreener UK

12 Irish Revolut customers said to be impacted by breach

Revolut confirms customer data breach through fake government requests | TechCrunch

Frequently Asked Questions

Stocks fall as Fed delivers hawkish rate hike

Dollar rises after Fed hikes rates in bid to counter inflation

Large crowd demands justice for assassinated Malta journalist

BYD will eventually need three assembly plants, one battery factory in Europe, adviser says

MMG hit with EU antitrust warning over nickel deal with Anglo American

France to extend targeted fuel aid measures until end of year

Explore more articles in the Finance category

Extracted Entities

Attack Types (1)

Companies (1)

Countries (1)

Industries (1)

MITRE ATT&CK (1)