Key Points
- A hacking group named iamnotavillain is demanding 6,000 XMR, equivalent to $3 million, within a day.
- They claim to have utilized blockchain analysis to identify Revolut accounts with significant cryptocurrency assets.
- Revolut has stated that it has not been in direct contact with the group nor received any ransom demands.
A criminal organization has issued a 24-hour ultimatum to Revolut, demanding a ransom of $3 million in Monero, threatening to sell sensitive customer information to other criminals if their demand is not met, as reported by the Financial Times.
The group announced their demand on a specially created website, specifying "6,000 XMR / $3,000,000" and ominously warned that failure to comply would result in the sale of all data, stating, "the blood will be on your hands."
Monero is known as a privacy coin, designed to obscure transaction details such as sender, recipient, and amount through technologies like ring signatures and stealth addresses. Major cryptocurrency exchanges, including Binance, Coinbase, and Kraken, have delisted it.
Extortion groups often prefer Monero for ransom payments and may even offer discounts for those who pay in it, as noted by TRM Labs. However, Bitcoin remains the most common choice for ransoms due to its easier accessibility and liquidity.
This incident stands out due to the methodical approach taken by the hackers in selecting their targets. The group informed the FT that they conducted blockchain analysis to identify Revolut customers with substantial holdings before targeting those accounts.
Details of the Revolut Breach
Revolut provided the compromised data after responding to requests from what appeared to be a legitimate government email address, which was later revealed to be part of a sophisticated impersonation scam. The company characterized the incident as a "sophisticated external impersonation scam."
The FT reported that these requests originated from a compromised Italian government email system and occurred over several months, affecting at least 680 accounts.
The stolen information is extensive, comprising names, birthdates, job titles, home addresses, copies of passports or driving licenses, selfies submitted for verification, account statements with IBANs and wallet identifiers, withdrawal records, and complete transaction histories. The hackers have provided the FT with a screen recording showing the stolen files.
Myriad: Where does crude oil go next? Click to make your prediction.ZachXBT, a blockchain investigator who first reported on the customer notification, noted that the breach seemed to specifically target high-net-worth individuals, corroborating the hackers' claims of their selection process. The combination of verified identities, home addresses, and substantial holdings raises concerns about the increase in violent wrench attacks against known cryptocurrency holders.
In a statement on Wednesday evening, Revolut asserted that it "has not received any direct contact or demand from the individuals or group making these claims." The company indicated that the number of affected customers is "limited," and confirmed that funds and systems remain secure, while opting not to disclose the name of the agency involved.
