Skip to content
Revolut Hackers Demand $3 Million Ransom for Customer Data

Revolut Hackers Demand $3 Million Ransom for Customer Data

First seen 16 Sep 2026, 20:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 16, 2026 at 22:55 UTC
  • Hackers demand $3 million in Monero from Revolut within 24 hours.
  • Breach affected 680 customer accounts, exposing sensitive data.
  • Attackers used fraudulent requests impersonating a government agency.

Hackers claiming to be from the group 'iamnotavillain' have demanded $3 million in Monero from Revolut within 24 hours, threatening to sell stolen customer data if the ransom is not paid. The breach affected at least 680 customer accounts, exposing sensitive information such as identity documents and transaction histories. The attackers used blockchain analysis to target accounts with significant crypto holdings. Revolut confirmed that the breach did not involve hacking its core infrastructure but resulted from fraudulent requests mimicking a legitimate government agency. The company has blocked the fraudulent email source and notified affected customers, emphasizing that customer funds remain secure. As of now, Revolut has not received any direct ransom demand from the attackers despite their public ultimatum.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
Hackers demand ransom from Revolut
The group 'iamnotavillain' publicly demanded $3 million in Monero, threatening to sell stolen data.
Coindesk
2026-09-16
Revolut confirms data breach details
Revolut stated that no direct ransom demand was received and that the breach resulted from fraudulent requests.
Globalbankingandfinance

More articles in this cluster (5)

Following this threat?

Track Revolut in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed