A hacking group known as iamnotavillain has demanded that Revolut pay 6,000 Monero (XMR), approximately valued at $3 million, threatening to sell client data to other criminal organizations. This information was reported by the Financial Times, which examined the ultimatum released by the hackers.

The threat was posted on the hackers' website on September 16, accompanied by a countdown timer. They granted Revolut a 24-hour timeframe to comply with their demands.

"6,000 XMR / $3,000,000... otherwise we will sell all the data, and the blood will be on your hands," the hackers stated.

Members of iamnotavillain claimed responsibility for a recent data breach and stated that they had not engaged in negotiations with the company prior to their ultimatum.

However, Revolut clarified that it had not received any direct communications from the group.

"Revolut has not received any direct messages or demands from individuals or groups making these claims," a representative of the fintech company told Reuters.

Details of the Data Breach

According to the Financial Times, the alleged breach affected around 680 Revolut clients. The iamnotavillain group provided the publication with a screen recording purportedly showing:

  • passports and driver's licenses;
  • identity verification photos;
  • contact and banking details;
  • transaction history.

The group claimed to have targeted clients using blockchain analysis, focusing on those with substantial cryptocurrency holdings.

The majority of the affected individuals reside in Switzerland and France, with others spread across 31 countries, primarily in Europe, according to iamnotavillain.

Among those notified of the breach was former Mt. Gox CEO Mark Karpeles, who criticized Revolut for providing information based on a request sent from an official government address.

How the Breach Happened

On September 12, on-chain researcher ZachXBT indicated that Revolut may have accepted fraudulent requests from a government entity as legitimate.

The disclosed information included names, contact details, copies of documents, verification selfies, bank statements, and complete transaction histories, including Bitcoin transfers.

Later, Revolut confirmed that sensitive information had been shared with unauthorized parties. The requests came through a legitimate domain of a government agency and passed the company's internal verification process.

According to independent media outlet International Cyber Digest, the group accessed an address within Italy's certified electronic mail system, PEC. For months, the hackers allegedly posed as law enforcement officials to request information regarding selected clients.

Revolut did not confirm these details, stating that its internal infrastructure and databases were not breached and that user funds remained unaffected.

Upon discovering the fraudulent requests, the fintech firm blocked the address used and notified the relevant government agency, law enforcement, as well as financial regulators and data protection services.

It is worth noting that in September, a class-action lawsuit was filed against hardware wallet manufacturer Ledger. The plaintiff claims that a 2023 incident revealed names, email addresses, phone numbers, and other personal information of clients. The complaint also references a 2020 breach that affected approximately 270,000 individuals.