Industry News

Revolut Faces $3 Million Ransom Demand After Customer Data Breach

Crypto news · 17 Sept 2026
Key Takeaway Even with strong technical defences, businesses should independently verify identity and authority before releasing customer data in response to any official-looking request, no matter how legitimate the sender's credentials appear.

A group calling itself "iamnotavillain" has demanded 6,000 Monero, worth roughly $3 million, from digital bank Revolut, threatening to sell stolen customer records to other criminal groups if payment is not made within 24 hours. Monero was chosen because it is designed to hide details of who sends and receives funds, making payments harder to trace.

The group shared a screen recording appearing to show passports, driving licences, KYC photos and transaction histories, and at least 680 accounts are known to be affected, though Revolut describes this as a small portion of its customer base. The UK's Information Commissioner's Office has opened an investigation.

Importantly, Revolut says its own systems and customer funds were not hacked. Instead, attackers impersonated a government agency using an email domain with valid authentication credentials, tricking Revolut into handing over customer data through what looked like a legitimate official request. Once discovered, Revolut blocked the email address and notified the agency, law enforcement, data-protection authorities and financial regulators.

Summarised by CISO AI from Crypto news. We link back to every original so you can read it yourself.