Hackers calling themselves "iamnotavillain" are demanding a $3 million ransom in Monero (6,000 XMR) from fintech giant Revolut, threatening to sell stolen customer data if not paid within 24 hours. The breach compromised at least 680 accounts, specifically targeting high-net-worth crypto holders identified via blockchain analysis. Attackers bypassed security checks by sending fake European Investigation Orders from a compromised Italian government email domain. Revolut states its core systems are safe and that it has received no direct ransom demands.
Three million dollar ransom
- ▪The hacker group "iamnotavillain" published its $3 million ransom demand on a public website alongside a 24-hour countdown clock on September 16, 2026
- ▪A cybercriminal group calling itself "iamnotavillain" demanded a $3 million ransom from Revolut, threatening to sell the stolen customer data to other criminals
Monero cryptocurrency payment demand
- ▪Monero is a privacy-focused cryptocurrency that obfuscates sender, recipient, and transaction amount details using ring signatures and stealth addresses
- ▪The hacker group "iamnotavillain" demanded that the $3 million ransom from Revolut be paid specifically as 6,000 Monero (XMR)
Crypto holder targeting strategy
- ▪On-chain investigator ZachXBT stated that the Revolut breach involving "iamnotavillain," which affected at least 680 customer accounts, appeared to be a deliberate, targeted attack against high-net-worth cryptocurrency users
- ▪Former Mt. Gox executive Mark Karpeles confirmed he was among the Revolut customers notified that their personal data and Bitcoin transaction histories were exposed
Customer identity document exposure
- ▪The Revolut customer data compromised in the breach by hackers calling themselves "iamnotavillain" includes names, dates of birth, home addresses, passport copies, driving licenses, verification selfies, and transaction histories
- ▪The hacker group "iamnotavillain" sent the Financial Times a 60-second screen recording showing a cache of the Revolut customer documents stolen in the data breach to prove the breach
Debatable claims
- ▪Revolut should refuse to pay the $3 million ransom demand
- ▪Financial institutions should be prohibited from permanently storing customer KYC documents
Story comments
Loading comments…