Revolut Hit With 6,000 XMR Ransom Demand as Hackers Threaten to Sell Customer Data
Criminals have given Revolut a 24-hour deadline to pay roughly $3 million in the privacy coin Monero, threatening to sell hundreds of customers’ identity documents and transaction records to other criminal groups, Decrypt reported.
The demand, posted Wednesday on a site the group built for the purpose, asks for “6,000 XMR / $3,000,000” and warns that otherwise “all the data will be sold, and the blood will be on your hands.” The group behind it calls itself iamnotavillain.
Also read: Internet Computer Tops Web3 Transactions With 134.5M in 24 Hours as ICP Stays Below $3
Revolut said Wednesday evening that it “has not received any direct contact or demand from the individuals or group making these claims,” and has described the number of affected customers as “limited.”
Key facts

- iamnotavillain demanded 6,000 XMR, about $3 million, within 24 hours.
- Roughly 680 Revolut accounts were affected, per the Financial Times.
- Revolut said the data was handed over in response to requests sent from a genuine government agency email domain as part of a “sophisticated external impersonation scam.”
- The group told the FT it used blockchain analysis to pick Revolut customers whose on-chain activity suggested substantial crypto holdings.
- Blockchain investigator ZachXBT, who first circulated the customer notification, said the breach appeared “targeted at high net worth users.”
What the group asked for, and what it did first
The extortion attempt is unusual less for its size than for how the victims were selected. The group told the FT it scanned the blockchain first to identify Revolut customers with large holdings, then went after those specific accounts. ZachXBT’s assessment that the breach was aimed at high net worth users lines up with that account.
Also read: BNB Tests $750 After Sharp Rebound — What the Chain Data Says About the Next Move
Monero was a deliberate choice. It obscures sender, recipient and amount through ring signatures and stealth addresses, and it has been delisted by Binance, Coinbase and Kraken. Extortion groups request it and sometimes discount demands for victims who pay in it, according to TRM Labs, though most ransoms still settle in Bitcoin, which TRM describes as far easier to acquire, move and convert at scale.
Cointribune reported that an earlier demand for 10,000 BTC circulated on Telegram, and that the authors of the current ultimatum say that figure came from an imposter or a former associate.
How the data left Revolut
The leak did not come from an intrusion into Revolut’s systems. The company has said the requests arrived from a real government agency domain with valid authentication, sent over a period of months. Cointribune reported that they exploited the Italian certified email system PEC, with attackers posing as law enforcement representatives. Revolut has declined to name the agency involved.
The exposed files are extensive: names, dates of birth, occupations, home addresses, passport or driving licence copies, verification selfies, account statements with IBANs and wallet references, withdrawal records and full transaction histories. Cointribune reported that those affected are mainly in France and Switzerland, along with several dozen other European countries. The hackers have shown the FT a screen recording of the files.
Revolut said its systems and customer funds were not compromised. It said it blocked the address used for the fake requests and alerted authorities, financial regulators and data protection bodies.
Cointribune noted that the case echoes a separate February incident in which a former Revolut employee was accused of using KYC data to pressure a crypto investor.
Why it matters
A verified name, a home address, a passport image and a proven crypto balance in one file set is the exact profile that has driven a rise in violent attacks on known crypto owners. Those records remain usable long after any ransom deadline passes, which is why the ransom demand may be the least important part of the story for affected customers. It also lands while Revolut is expanding its digital asset business, putting data handling rather than custody or trading at the centre of its risk.
What to watch
The 24-hour deadline posted Wednesday is the immediate trigger point: whether the group publishes or sells the files, and whether Revolut’s position that its systems and funds were untouched holds. Regulators and data protection bodies that Revolut says it alerted are the other track to follow.
Sources: Decrypt, Cointribune
