Industry News

Extortion Group Demands $3M in Monero After Revolut Data Leak

Cointribune · 17 Sept 2026
Key Takeaway Businesses should train staff to independently verify law enforcement or government data requests through official channels before releasing any customer information, no matter how legitimate the request appears.

Revolut is facing a fresh crisis after a group calling itself iamnotavillain published a 24-hour ultimatum demanding 6,000 Monero (XMR), worth roughly $3 million, threatening to sell stolen customer data to other criminal groups if the fintech does not pay. Revolut says it has not received any ransom request through its own channels and that no systems or client funds were compromised.

The underlying leak did not stem from a typical system intrusion. Revolut confirmed on September 12 that it had handed sensitive customer information to an unauthorised party after receiving fraudulent requests appearing to come from a legitimate government email domain, reportedly abused via Italy's certified email system, PEC. Posing as law enforcement, the attackers targeted specific clients over several months, obtaining data including birth dates, addresses, phone numbers, passport and driver's licence copies, and transaction histories including crypto activity. About 680 people are affected, mainly in France and Switzerland but also across other European countries, with attackers claiming to have used blockchain analysis to identify clients with significant crypto holdings.

The choice of Monero, a cryptocurrency built to obscure transaction details unlike the more transparent bitcoin, suggests the attackers are prioritising anonymity as they attempt to monetise the stolen data. An earlier, separate ransom demand of 10,000 BTC circulated on Telegram is said to have come from an impersonator unrelated to this group.

Regulated in financial services? APRA CPS 220, 230 and 234, in plain language ->

Summarised by CISO AI from Cointribune. We link back to every original so you can read it yourself.