
The group iamnotavillain has demanded 6000 Monero (XMR) tokens, worth approximately $3 million, from Revolut and threatened to sell customer data to other criminal organizations. This was reported by Financial Times, which reviewed the ultimatum published by the hackers.
The message appeared on September 16 on the cybercriminals’ website along with a countdown. The perpetrators gave Revolut 24 hours to transfer the funds.
“6,000 XMR / $3,000,000… or we will sell all the data, and the blood will be on your hands,” the hackers’ message stated.
Representatives of iamnotavillain claimed responsibility for the recent data breach and stated that they had not negotiated with the company before issuing the ultimatum.
Meanwhile, Revolut clarified that they had not received any direct communications from the group.
“Revolut has not received any direct messages or demands from the individuals or group making these claims,” a spokesperson for the fintech company told Reuters.
Data Compromised by Hackers
According to Financial Times, the alleged breach affected about 680 Revolut customers. The iamnotavillain group provided the publication with a one-minute screen recording that purportedly showed:
- passports and driver’s licenses;
- identity verification photos;
- contact and banking details;
- transaction history.
The group claims they selected targets using blockchain analysis, focusing on Revolut customers with significant cryptocurrency holdings.
Most of the affected individuals reside in Switzerland and France, with others located in 31 predominantly European countries, according to iamnotavillain.
Among those notified of the breach was former Mt.Gox CEO Mark Karpeles, who criticized Revolut for releasing information based on a request sent from an official government address.
How the Breach Occurred
On September 12, on-chain researcher ZachXBT reported that Revolut may have mistaken fake government requests for legitimate ones.
The disclosed information reportedly included names, contacts, document copies, verification selfies, bank statements, and a complete transaction history, including Bitcoin transfers.
Later, Revolut confirmed the release of confidential information to outsiders. The requests came through a legitimate government domain and passed the company’s internal checks.
According to independent media International Cyber Digest, the group gained access to an address in the Italian certified email system PEC. For several months, the hackers allegedly posed as law enforcement officials and requested information about selected clients.
Revolut did not confirm these details. The company stated that its internal infrastructure and databases were not breached, and user funds were not affected.
After discovering the fake requests, the fintech firm blocked the used address and notified the relevant government agency, law enforcement, financial regulators, and data protection services.
In September, a class-action lawsuit was filed against hardware wallet manufacturer Ledger. The plaintiff claims that the 2023 incident exposed names, email addresses, phone numbers, and other personal data of clients. The complaint also mentions a 2020 breach affecting about 270,000 people.
