Markets Hackers Demand $3 Million in Monero from Revolut, Threaten Data Sale

The group has given Revolut a 24-hour deadline to comply, specifically targeting customers with large crypto assets.

By Helene Braun, AI Boost|Edited by Cheyenne Ligon 52 min ago 1 min read

  • Cybercriminals are asking for $3 million in Monero (XMR) within a day, threatening to sell stolen data if their demand is not met.
  • The breach has reportedly impacted at least 680 customer accounts, with sensitive data such as identity documents and transaction histories exposed.
  • The hackers indicated they utilized blockchain analysis to identify Revolut accounts with substantial cryptocurrency holdings.

A group of hackers responsible for a data breach at Revolut is demanding a ransom of $3 million in Monero (XMR) within a 24-hour period, threatening to sell the compromised customer data to other criminal entities if Revolut does not comply, according to a report by the Financial Times.

Identifying themselves as “iamnotavillain,” the hackers issued their demand along with a countdown timer on Wednesday, requesting the transfer of 6,000 XMR, which is a cryptocurrency known for its privacy features.

The breach has affected no fewer than 680 accounts, as reported.

The hackers disclosed to the Financial Times that they used blockchain analysis techniques to select their targets, specifically focusing on accounts with significant cryptocurrency assets.

They also shared a brief video with the FT, showcasing some of the sensitive data they obtained, which included passports, driving licenses, images used for identity verification processes, and transaction records.

This incident occurred after the attackers impersonated government officials and successfully submitted fraudulent requests for customer information that passed through Revolut's security checks. The company provided customer records before realizing the requests were not legitimate, as indicated in prior notifications sent to affected customers.

Revolut has previously stated to CoinDesk that it has blocked the IP address used in the fraudulent requests and has alerted the relevant government authority, law enforcement, and regulatory bodies. The company asserts that its systems and customer funds remain secure.

At the time of the publication, the hackers mentioned that no negotiations with Revolut had taken place.

Revolut has not responded to CoinDesk's inquiry for comments prior to publication.