Industry News

Revolut Hit by Extortion Attempt After Fraudsters Posed as Government Officials

Coindesk · 17 Sept 2026
Key Takeaway Businesses should treat requests for customer data, even those appearing to come from government agencies, with strict verification procedures before releasing any information.

A hacking group calling itself “iamnotavillain” is demanding $3 million worth of the cryptocurrency Monero from digital bank Revolut, threatening to sell stolen customer data to other criminal groups if the demand is not met within 24 hours, according to the Financial Times. The attackers claim to have targeted at least 680 Revolut customer accounts, reportedly selecting victims by using blockchain analysis to identify accounts holding significant amounts of cryptocurrency.

The breach reportedly occurred after attackers impersonated government officials and submitted information requests that passed Revolut's verification checks. Revolut handed over customer records before realising the requests were fraudulent. Data allegedly obtained includes passports, driving licences, identity verification photos and transaction histories.

Revolut has said it blocked the address used to submit the fraudulent requests and notified the relevant government agency, law enforcement and regulators. The company maintains that its systems and customer funds were not affected, and it had not entered negotiations with the attackers at the time of reporting.

Summarised by CISO AI from Coindesk. We link back to every original so you can read it yourself.