Back Finance.Biggo Revolut Hackers Post Public $3 Million Monero Ransom Demand With 24
A hacker group calling itself "iamnotavillain" has gone public with an unusual extortion demand against Revolut, threatening to sell stolen customer records to other criminal networks unless the British fintech pays 6,000 Monero tokens, worth roughly $3 million, within 24 hours.
The ultimatum appeared Wednesday alongside a live countdown clock, according to an investigation published by the Financial Times. The attackers told the newspaper they had not entered into any negotiations with Revolut at the time of publication, and the company separately told Reuters it had received no ransom demand or direct from the group.
Revolut has maintained that its core systems and customer funds were not compromised. The incident stemmed instead from a social-engineering scheme in which the attackers posed as government officials and submitted fraudulent information requests that cleared the company's authentication checks. Revolut supplied customer records before realizing the requests were fake, then blocked the originating email address and alerted the relevant government agency, law enforcement, data-protection authorities and financial regulators.
At least 680 customer accounts were affected, though Revolut has publicly described the number only as a "very limited" portion of its customer base, which now exceeds 80 million users worldwide. Britain's Information Commissioner's Office opened an investigation after the company reported the incident to regulators.
The stolen material reportedly includes passports, driving licences, photographs submitted during know-your-customer checks, and complete transaction histories. Some account statements also contained Bitcoin wallet reference numbers and records of Bitcoin transactions. Revolut's customer notice distinguished identity-check photographs from biometric facial telemetry data, which the company said was not part of the disclosure. Private keys, passwords, security codes and complete payment-card details were also not identified among the exposed information.
The hackers provided the Financial Times with a 60-second screen recording that appeared to display portions of the material in their possession. The video showed identity documents, KYC photos and transaction histories, according to the report.
Targeting crypto-rich accounts
The group said it used blockchain analysis to select Revolut customers who appeared to hold substantial amounts of cryptocurrency. That account, if accurate, would indicate the affected group was chosen partly through financial activity rather than collected at random. On-chain investigator ZachXBT had previously said the incident appeared to involve high-net-worth users, an assessment Revolut has not confirmed.
The disclosed records may contain both sides of a dangerous connection. Identity documents and information can identify an account holder, while Bitcoin transaction histories and wallet reference numbers can map parts of that person's crypto activity. Combined, the two data sets could allow criminals to craft highly convincing phishing messages containing a real name, transaction detail or identity document.
The choice of Monero as the demanded payment currency is deliberate. Unlike Bitcoin or Ethereum, where transaction trails are publicly visible, Monero makes privacy mandatory at the protocol level. Ring signatures obscure the true sender among a group of possible participants, stealth addresses hide the recipient's public address, and Ring Confidential Transactions conceal the amount sent. That design removes the investigative lever law enforcement has used to trace ransom payments on transparent networks.
Criminal use of XMR does not establish that the token or all of its users are engaged in illegal activity. Monero also serves people seeking financial privacy, but its design can make illicit payment trails more difficult for investigators to follow. A separate August case illustrated the same challenge after investigators said assets from a reported $7.9 million Coinsbuy hack were converted into Monero, with blockchain firms tracking portions of those funds through several exchanges before some assets were reportedly exchanged for XMR.
The public nature of the demand is itself notable. Hackers typically make ransom requests privately and only go public if a target refuses to pay or engage. By publishing a countdown timer and threatening to sell the data to other criminal groups, iamnotavillain appears to be applying maximum pressure from the outset.
Broader risk beyond the ransom
The selective targeting of high-value crypto accounts adds a layer of risk beyond the immediate extortion. Chainalysis has reported that violent "wrench attack" victims are often selected using information from data breaches, social media or insiders, with more than $30 million estimated stolen in such attacks by mid-2026. Verified identity documents also command high prices on underground markets regardless of whether a ransom is paid.
UK and European Union regulators have scheduled supervisory hearings on the incident toward the end of the third quarter of 2026. The extortion demand denominated in a privacy coin creates additional compliance friction in jurisdictions that already treat Monero with heightened regulatory scrutiny, particularly as Revolut continues expanding its regulated product suite across Europe, including its EURR euro stablecoin.
For affected customers, the practical risk centers on identity documents and KYC photos rather than funds. Revolut's U.S. security guidance says the company will not unexpectedly call customers and ask them to make a payment or disclose verification and security codes. The Federal Trade Commission directs consumers whose personal or banking information has been exposed to IdentityTheft.gov, while the FBI's Internet Crime Complaint Center asks people reporting cryptocurrency-related fraud to provide wallet addresses, transaction amounts, asset types, transaction hashes, and the dates and times of transfers when available.
Revolut did not respond to requests for from multiple outlets by publication time.
Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
