Ransom Demand and Escalating Threat
A criminal group identifying itself as "iamnotavillain" has issued a 24-hour ransom demand against the UK-based neobank Revolut, calling for the payment of 6,000 Monero (XMR) — roughly $3 million — in exchange for not distributing stolen customer data. According to the Financial Times, the hackers posted the ultimatum on Wednesday alongside a live countdown clock, explicitly warning that if Revolut does not comply, the compromised records will be sold to other criminal organisations. The choice of Monero, a privacy-focused cryptocurrency engineered to conceal the origin and destination of transactions, is a deliberate tactic to make tracing the payment extremely difficult for law enforcement.
As of the FT's reporting, the group stated that no negotiations had taken place with Revolut at the time the article was published.
How the Breach Was Executed
The attack vector is particularly concerning for anyone managing digital assets through institutional or semi-institutional channels. The perpetrators impersonated government officials and submitted information requests that successfully passed Revolut's internal verification procedures. The bank processed the requests and handed over customer records before the fraudulent nature of the inquiries was discovered, as confirmed by notices Revolut later sent to the affected individuals.
What makes the targeting especially noteworthy is the method the hackers used to select their victims. Speaking to the FT, the group explained that it employed blockchain analysis to identify Revolut accounts holding significant cryptocurrency balances. This signals a shift toward more sophisticated, data-driven threat actors who combine on-chain forensics with social-engineering attacks to maximise the value of stolen information.
Scope of the Data Exposure
At least 680 Revolut customer accounts were compromised in the incident. To substantiate their claim of possession, the hackers provided the FT with a 60-second screen recording that appeared to display portions of the stolen material. The footage reportedly included passport documents, driving licences, photographs used for know-your-customer (KYC) verification, and detailed transaction histories.
For traders and retail investors, the combination of verified identity documents and granular transaction data creates a high-risk profile for follow-on fraud, including identity theft, targeted phishing, and account-takeover attempts at exchanges or other financial platforms.
Revolut's Response and What Customers Should Monitor
Revolut previously told CoinDesk that it had blocked the address associated with the fraudulent requests and notified the relevant government agency, law enforcement bodies, and financial regulators. The company stressed that its core systems and customer funds remained unaffected by the incident.
From a scam-alert perspective, holders of Revolut accounts — particularly those with meaningful crypto portfolios — should remain vigilant in the coming weeks. The threat of the data being resold to secondary criminal groups elevates the risk of phishing emails, fake support calls, and credential-harvesting sites impersonating Revolut or crypto exchanges. Customers should verify any unsolicited communication through official channels, enable multi-factor authentication wherever possible, and monitor their accounts for unauthorised access or unusual transaction activity.