- Hackers are demanding 6,000 XMR, worth about $3 million.
- The public ultimatum gives Revolut 24 hours to pay.
- About 680 customers were reportedly affected.
- UK regulators are examining the incident.
Hackers claiming access to data from Revolut customers have demanded 6,000 Monero worth about $3 million, threatening to sell the information to other criminal groups if the fintech does not pay within 24 hours.
A group calling itself “iamnotavillain” published the demand on a website with a countdown timer.
Revolut said on Thursday that it had received no direct contact or ransom demand from the people making the claims, meaning the ultimatum remains a public extortion attempt rather than a demand delivered privately to the company.
The incident is drawing additional scrutiny because the attackers did not need to compromise Revolut’s banking infrastructure. Sensitive information was released after fraudulent requests arrived through a legitimate government email domain, exposing a weakness in how privileged requests for customer data are authenticated.
What Revolut Has Confirmed
Revolut confirmed on September 12 that an unauthorized party used a legitimate government agency email domain to submit fraudulent information requests. The company blocked the address after detecting the activity and alerted the relevant government agency, law enforcement and regulators.
Customer notifications reviewed by TechCrunch showed that exposed information could include dates of birth, postal and email addresses, phone numbers and copies of identity documents such as passports and driver’s licenses. Verification selfies, account statements and transaction histories may also have been disclosed.
Revolut says its systems and customer funds were unaffected. The company has not publicly confirmed the precise number of victims, describing the affected population as limited. The Financial Times reported that around 680 customer accounts were involved.
The regulatory response is already underway. The UK’s Information Commissioner’s Office is investigating the incident, while cybersecurity firm Kodex reported that the Financial Conduct Authority had also confirmed an investigation.
How Fraudulent Government Requests Can Expose Customer Data
The attack targeted a process designed to let financial institutions respond to legitimate requests from law-enforcement and government agencies.
According to Revolut’s notification, the fraudulent requests carried valid domain authentication credentials. That can establish that an email originated from an authorized domain, but it does not necessarily prove that the person controlling the account is a legitimate official entitled to request the information.
Kodex founder and former FBI official Matt Donahue describes the technique as law-enforcement email compromise, or LEEC. Kodex says it has identified more than 5,000 criminals impersonating law enforcement to obtain customer information.
This attack vector sits outside the controls normally associated with preventing a network intrusion. Firewalls, wallet security and customer authentication do not solve the problem if an institution voluntarily releases information after treating a fraudulent legal request as genuine.
Verification therefore has to occur at the disclosure layer. Security specialists recommend independently confirming the identity and authority of the requester rather than treating possession of an authenticated government email account as sufficient evidence.
Crypto Holders Were Reportedly Targeted
The Financial Times reported that the attackers claim they used blockchain analysis to identify customers with substantial cryptocurrency activity before requesting their information. Most affected customers were reportedly based in Switzerland and France, although records from people across dozens of European countries were involved.
If accurate, that would make the exposed information particularly sensitive.
Crypto transactions on transparent blockchains can already provide clues about holdings and activity. Connecting that information with KYC records, physical addresses, identification documents and financial histories can give criminals a much more complete profile of an individual.
Some affected customers have consequently raised concerns about physical extortion, including so-called wrench attacks against cryptocurrency holders.
Why the Attackers Want Monero
The latest demand replaces an earlier reported demand for 10,000 BTC, although responsibility for the competing claims remains disputed. Kodex cautioned that the people publicizing samples of the stolen information cannot automatically be assumed to be the original attackers, while possession of a sample does not establish possession of the entire dataset.
The new group is asking for Monero rather than Bitcoin.
Bitcoin’s ledger publicly records transactions, allowing investigators and blockchain analytics firms to follow the movement of funds even when the identity controlling an address is initially unknown.
Monero is specifically designed to obscure transaction information. Its privacy mechanisms make the sender, recipient and transferred amount considerably harder to trace, which explains its attraction for extortion payments as well as its legitimate privacy uses.
The 6,000 XMR demand shown in the attackers’ public ultimatum was valued at approximately $3 million when issued.
What Affected Revolut Customers Should Do
Revolut says it has contacted affected customers directly, so an unsolicited message claiming that someone was exposed should not itself be treated as proof.
Customers who received a genuine breach notification should treat exposed identity and contact information as potentially usable for targeted phishing and account-recovery fraud. Practical precautions include changing reused passwords, enabling strong two-factor authentication, reviewing Revolut and other financial accounts for unfamiliar activity, and being especially cautious about calls or messages referencing genuine personal information from the breach.
Crypto holders should also review the security of accounts connected to their phone number and email. Where supported by their mobile carrier, additional protection against unauthorized SIM replacement can reduce SIM-swap risk. Exchange accounts should use phishing-resistant authentication where available rather than relying solely on SMS codes.
Moving cryptocurrency simply because personal information was exposed is not automatically necessary, particularly if private keys were never compromised. But anyone whose leaked records could connect their identity to substantial crypto holdings should reassess whether public wallet activity reveals more about their assets than intended.
Most importantly, customers should not send cryptocurrency to anyone claiming they can recover, remove or protect leaked data. The disclosure itself gives criminals enough genuine personal information to make follow-up scams more convincing.
The 24-Hour Deadline Does Not End the Risk
Whether the attackers carry out their threat remains unknown. Revolut has not confirmed the group’s claims about the full dataset, and questions remain over whether the current extortionists were responsible for obtaining all of the information in the first place.
The regulatory investigation now has a more concrete control question: how was a request from a legitimate government domain authenticated before sensitive customer records were released?
For financial companies handling government information requests, that distinction is increasingly important.
Valid email authentication can prove where a message came from. It cannot, by itself, prove who is operating the account or whether that person has legal authority to obtain the requested customer data.





Be the first to comment