Skip to content

Coins

Financial Times: Revolut Hackers Lower Ransom to $3M, Set 24-Hour Deadline

Revolut Data Breach: Hackers Demand $3 Million in Monero, Threaten to Sell 680 Customer Records A cybercrime group styling itself “iamnotavillain” has escalated its extortion campaign against British fintech firm...

Revolut Data Breach: Hackers Demand $3 Million in Monero, Threaten to Sell 680 Customer Records

A cybercrime group styling itself “iamnotavillain” has escalated its extortion campaign against British fintech firm Revolut, demanding 6,000 Monero (XMR) tokens—valued at approximately $3 million as of September 16, 2026—in exchange for not selling confidential data belonging to roughly 680 customers. The attackers published a 24-hour countdown timer on an external website Wednesday, setting a deadline of Thursday, September 17, 2026, according to a Financial Times investigation.

Ransom Demand and Cryptocurrency Choice

The ransom note specifies payment in Monero, a privacy-focused cryptocurrency selected for its anonymity and cryptographic protocols that obscure transaction trails. A 60-second screen recording provided to the Financial Times reportedly displayed compromised documents including passports, driver’s licenses, and complete banking records.

Revolut has stated officially that it has not received any direct demand from the extortionists. A company spokesperson confirmed that core infrastructure and primary databases suffered no unauthorized access, suggesting the breach may be limited to a specific compliance-related dataset.

Breach Vector: Government Domain Impersonation

The security incident originated from a fraudulent information request sent from a legitimate government domain. Compliance staff processed the request before identifying the identity spoofing, allowing the attackers to extract sensitive customer information. Revolut has since blocked the compromised domain and formally alerted law enforcement authorities.

Scope of Compromised Data

Official company disclosures indicate the leaked dataset includes:

  • Full names, residential addresses, and phone numbers
  • Identity verification photographs
  • IBAN numbers and account opening dates
  • Account statements referencing Bitcoin transfers

The attackers told the Financial Times they used on-chain analytics to specifically target customers with significant digital asset holdings. Prior reporting by on-chain investigator ZachXBT suggests the affected accounts correspond to high-net-worth profiles, indicating a highly targeted operation rather than a broad data dump.

Regulatory Response and Timeline

The UK Information Commissioner’s Office (ICO) maintains an open formal investigation into the matter. UK and European Union regulators have scheduled supervisory hearings on the incident toward the end of the third quarter of 2026, signaling heightened regulatory scrutiny of fintech data protection practices.

The extortionists’ ultimatum expires Thursday, September 17, 2026. Whether Revolut engages with the demand or relies on law enforcement intervention remains unresolved as the countdown continues.

Evan Mercer

Penulis

Evan Mercer covers coins, digital assets and the market stories shaping everyday conversations about money. His work focuses on accessible explanations, useful context and the signals behind sudden moves.