A criminal group calling itself iamnotavillain has demanded 6,000 XMR—approximately $3 million—from Revolut within 24 hours, threatening to sell customers' identity documents and transaction records if the demand is not met, according to the Financial Times.
The demand was posted Wednesday on a website created by the group. It specifies "6,000 XMR / $3,000,000" and warns that "all the data will be sold, and the blood will be on your hands" if payment is not received.
Monero, a privacy-focused cryptocurrency, obscures sender, recipient, and transaction amounts through ring signatures and stealth addresses. The coin has been delisted by major exchanges including Binance, Coinbase, and Kraken.
Targeted Selection
What distinguishes this breach is the method used to select victims. The group told the FT it conducted blockchain analysis first, identifying Revolut customers whose on-chain activity indicated substantial holdings before targeting those specific accounts.
How the Data Was Accessed
Revolut stated the data was obtained through "a sophisticated external impersonation scam." The company said attackers responded to information requests sent from a compromised Italian government email system using a genuine government domain and valid authentication. The requests were made over several months, affecting at least 680 accounts.
The stolen data included names, dates of birth, occupations, home addresses, passport or driving licence copies, verification selfies, account statements with IBAN and wallet references, withdrawal records, and full transaction histories. The hackers provided the Financial Times with a screen recording of the files as evidence.
Revolut's Response
Revolut said Wednesday evening it "has not received any direct contact or demand from the individuals or group making these claims." The company described the number of affected customers as "limited" and stated that funds and systems were untouched. It declined to name the government agency involved.
Blockchain investigator ZachXBT, who first shared the customer notification, said the breach appeared "targeted at high net worth users," consistent with the group's account of its selection process.


