Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Revolut Attackers Shift Ransom Demand to 6,000 Monero After Social Engineering Breach

Hackers claiming responsibility for accessing Revolut customer data now demand 6,000 XMR, roughly $3 million, after initially requesting Bitcoin. The attackers obtained records on approximately 680 users by impersonating Italian law enforcement through a legitimate government email system.
1 hour ago 8 views
Revolut Attackers Shift Ransom Demand to 6,000 Monero After Social Engineering Breach

Attackers who obtained customer data from Revolut have shifted their ransom demand from Bitcoin to 6,000 monero (XMR), valued at approximately $3 million. The hacking group, calling itself iamnotavillain, posted an ultimatum on September 16 with a 24-hour deadline to prevent the stolen files from being sold to other criminal groups.

According to statements made to the Financial Times, the attackers did not breach Revolut's security systems. Instead, they posed as Italian law enforcement officials for months, using Italy's Posta Elettronica Certificata (PEC) system—a certified-email network for legal and government communications—to request customer files. The compromised email channel carried legitimate domain authentication credentials, making the requests appear to come from genuine government authorities.

Targeted Data Collection

The attackers did not conduct a random data grab. Using onchain analysis, they identified Revolut users with significant cryptocurrency activity and requested records on those specific individuals by name. The affected group comprises approximately 680 people across 31 countries, with concentrations in Switzerland and France.

The stolen files allegedly include names, addresses, phone numbers, account IDs, cryptocurrency deposit and withdrawal records, fiat transfers, KYC documents, and verification selfies. Revolut maintained that its core systems and customer funds remained unaffected, and the company received no direct ransom demand when the public countdown appeared.

Implications for User Security

While customer funds appear secure, the combination of personal identification documents and financial transaction histories presents significant risk. The stolen records could enable account impersonation, unauthorized account resets, fraudulent support calls, and follow-on attacks against other financial services.

Revolut reported the incident on September 12 and blocked the malicious email address. Investigators are examining how a legitimate government communications channel was exploited for months. The incident raises questions about whether other cryptocurrency firms received similar impersonation requests through compromised official channels.

An earlier demand for 10,000 Bitcoin circulated on Telegram, but the group attributed this to an impersonator or former associate. The shift to monero—a privacy-focused cryptocurrency designed to obscure transaction details—aligns with the opacity typically sought in extortion demands, as Bitcoin transactions remain visible on a public ledger.

Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.