Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Revolut Hackers Demand $3 Million Ransom After Breaching Crypto Customer Data

Attackers claiming responsibility for a Revolut data breach are demanding $3 million in Monero cryptocurrency, threatening to sell records containing identity documents, addresses, and transaction histories of crypto-heavy accounts.
1 hour ago 15 views
Revolut Hackers Demand $3 Million Ransom After Breaching Crypto Customer Data

Hackers who obtained customer data from Revolut are demanding a $3 million ransom in Monero to prevent the information from being leaked publicly, according to reporting by the Financial Times. The group calling itself "iamnotavillain" has threatened to sell the stolen records if the payment is not made.

However, Reuters reported that Revolut has received no direct ransom demand or contact from the attackers. The company stated that around 680 customer files were compromised, though it has declined to provide specific numbers, characterizing the impact only as "limited."

What Data Was Exposed

The stolen information includes names, dates of birth, home addresses, phone numbers, identity documents, verification selfies, bank statements, and transaction records. Former Mt. Gox executive Mark Karpeles confirmed he was affected by the breach and shared a Revolut notification indicating that details about Bitcoin transactions had been exposed.

The attackers claimed to have hacked an email system belonging to a legitimate government agency and used blockchain analysis to identify Revolut customers with substantial cryptocurrency holdings, according to the Financial Times. Revolut has not confirmed these claims.

How the Breach Occurred

Revolut disclosed that its core systems and customer funds were not compromised. Instead, the breach resulted from fraudulent data requests submitted via email using a domain belonging to a legitimate government agency. The company characterized the incident as a "sophisticated external impersonation scam" and said it blocked the email address once the fraud was discovered.

Security Implications

Leaked personal addresses paired with evidence of large cryptocurrency holdings can create physical security threats. Chainalysis reports that many violent attacks targeting cryptocurrency holders are premeditated, with victims identified through leaked data, social media, blockchain analysis, or insider information.

The incident places pressure on centralized platforms to strengthen their procedures for verifying official data requests and limiting sensitive information exposure through compromised processes. The European Banking Authority ranks cyber risk and data security as the leading operational-risk driver for banks, followed by fraud.

Centralized exchanges remain the primary access point for cryptocurrency users, with research indicating that 73 percent of UK crypto users obtain assets through such platforms.

Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.