Revolut stated it has not received direct contact from or demands by any group claiming responsibility for a recent data breach affecting roughly 680 high-net-worth customers across Europe. The denial came after reports that hackers demanded 6,000 XMR, valued at approximately $3 million, in exchange for not releasing the stolen data.
The London-based fintech company confirmed that an unauthorized third party obtained sensitive customer information by using a legitimate government agency's email domain to submit fraudulent data requests. Hackers operating under the online handle "IAmNotAVillain" publicly threatened to release or sell customer data unless Revolut paid the ransom.
According to Revolut, the attackers used social engineering over several months to impersonate government authorities, obtaining customer verification files, identity documents, and transaction records. The breach did not involve a direct technical intrusion into Revolut's core systems. The company stated that customer funds and internal systems remain secure and unaffected, and it blocked the fraudulent email address upon discovering the incident.
Revolut reported the breach to law enforcement, data protection authorities, and financial regulators.
KYC Requirements Create Security Vulnerabilities, Analyst Warns
Jonathan Riss, an open-source and blockchain intelligence analyst at security firm Certik, argued that the incident highlights broader systemic vulnerabilities extending beyond individual companies' defenses to regulatory requirements themselves.
Riss stated that mandatory know-your-customer (KYC) rules require financial platforms to maintain an extremely sensitive identity data layer, often because governments and regulators demand increasingly detailed customer information. He contended that responsibility for data security does not rest solely with banks, fintechs, or cryptocurrency exchanges.
According to Riss, public authorities should reconsider whether every piece of information they require is genuinely necessary and how long it should be retained. They should also evaluate whether existing procedures for requesting customer data are sufficiently secure.
Riss noted that platforms should minimize data retention, restrict access, and strengthen authentication of government and law enforcement requests through independent verification channels. He suggested the incident should prompt the industry and regulators to rethink the current model to protect users' financial identities alongside protecting wallets and funds.


