Coindesk Revolut Hackers Demand $3 Million Ransom for Customer Data
Article Content
- •Hackers demand $3 million in Monero from Revolut within 24 hours.
- •Breach affected 680 customer accounts, exposing sensitive data.
- •Attackers used fraudulent requests impersonating a government agency.
Hackers claiming to be from the group 'iamnotavillain' have demanded $3 million in Monero from Revolut within 24 hours, threatening to sell stolen customer data if the ransom is not paid. The breach affected at least 680 customer accounts, exposing sensitive information such as identity documents and transaction histories. The attackers used blockchain analysis to target accounts with significant crypto holdings. Revolut confirmed that the breach did not involve hacking its core infrastructure but resulted from fraudulent requests mimicking a legitimate government agency. The company has blocked the fraudulent email source and notified affected customers, emphasizing that customer funds remain secure. As of now, Revolut has not received any direct ransom demand from the attackers despite their public ultimatum.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Revolut in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…