crypto for all
Join
A
A

Crypto: Hackers Hit Revolut with a $3M Monero Ransom Demand

13h23 ▪ 5 min read ▪ by Lydie M.
Getting informed Altcoins
Summarize this article with:

Revolut faces new pressure following a data leak revealed a few days earlier. A group calling itself iamnotavillain now demands 6,000 XMR. This is about 3 million dollars, and threatens to sell stolen information if the fintech does not pay. The attackers set a 24-hour deadline. About 680 clients, including several major crypto holders, are affected. Revolut states it has not received any request directly.

A cybersecurity team faces a M crypto ransom demand in Monero.

In brief

  • The attackers demand 6,000 XMR, about 3 million dollars.
  • About 680 Revolut clients would be affected by the leak.
  • Revolut assures that its core systems and clients’ funds were not hacked.

The attackers now demand 6,000 XMR

The case comes at a bad time for Revolut, which is rapidly expanding its activities related to digital assets. Cointribune detailed just this week Revolut’s expansion in crypto, between stablecoin, trading, and payments.

This time, the fintech mainly faces a case related to personal data. The iamnotavillain group published its ultimatum Wednesday on a site with a countdown. The hackers demand 6,000 Monero and state they will pass the files to other criminal groups if Revolut does not pay within 24 hours.

An initial request of 10,000 BTC had circulated earlier on Telegram. The authors of the current ultimatum say this sum came from an imposter or a former associate.

The choice of Monero is less surprising. Unlike bitcoin, whose transactions are publicly visible on the blockchain, the XMR crypto is designed to mask more information about transfers. Revolut states it had no direct contact with the group and has not received any ransom request through their own channels.

The hackers did not breach Revolut’s systems

The leak would not have originated from a classic intrusion. Revolut confirmed on September 12 that it transmitted sensitive information to an unauthorized person after receiving fake requests from a legitimate government email domain. Revolut assures that none of its systems nor clients’ funds were compromised.

The attackers allegedly exploited the Italian certified email system PEC. By pretending to be law enforcement representatives, they sent targeted requests regarding certain clients for several months.

Among the exposed information would be birth dates, postal and email addresses, phone numbers as well as copies of passports and driver’s licenses. Transaction histories and data related to crypto movements would also be part of the obtained files.

According to reported information, about 680 people are affected, mainly in France and Switzerland, but also in several dozen other European countries. The attackers say they used blockchain analysis to spot clients with significant activity in digital assets.

The case reminds of another recent one. In February, a former Revolut employee was already accused of using KYC data to pressure a crypto investor. Two different stories, with the same type of sensitive information at their center.

Monero crypto returns to the heart of an extortion case

The hackers are not demanding dollars, nor even bitcoins. They want the XMR crypto. Monero was designed with privacy as a core function. Several cryptographic mechanisms hide sender and receiver addresses as well as transferred amounts. This architecture explains why the token regularly appears in ransom cases or payments that their authors seek to make harder to trace.

That does not mean Monero offers perfect invisibility. Specialized companies have been working for several years on methods to reduce its anonymity.

Cointribune notably reported in 2024 that some Monero transactions could be tracked thanks to nodes and IP address analysis. In the Revolut case, the most sensitive point remains elsewhere: personal data. A passport, a full address, verification photos, and financial history can be used maliciously long after the expiry of an ultimatum. Revolut states it blocked the address used for fake requests and alerted authorities, financial regulators, and data protection bodies. At this stage, no evidence indicates theft of clients’ funds. The demand is now public: 6,000 XMR and 24 hours.

Maximize your Cointribune experience with our "Read to Earn" program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.



Join the program
A
A
Lydie M. avatar
Lydie M.

Enseignante et ingénieure IT, Lydie découvre le Bitcoin en 2022 et plonge dans l’univers des cryptomonnaies. Elle vulgarise des sujets complexes, décrypte les enjeux du Web3 et défend une vision d’un futur numérique ouvert, inclusif et décentralisé.

DISCLAIMER

The views, thoughts, and opinions expressed in this article belong solely to the author, and should not be taken as investment advice. Do your own research before taking any investment decisions.