Revolut Faces $3M Monero Ransom Demand Amid Compliance Concerns
A hacker group called iamnotavillain has threatened to sell stolen data on approximately 680 Revolut customer accounts unless the company pays a $3 million ransom in Monero (XMR).
The group claims it will release the sensitive information, including passports, driving licenses, KYC selfies, IBANs, account statements, and Bitcoin transaction histories, if the payment is not made within 24 hours.
Revolut has stated that its systems remain operational and that funds, passwords, private keys, and full card details were not compromised. However, the attack highlights a vulnerability in Revolut's law-enforcement request controls, which allowed attackers to send fraudulent data requests through a compromised Italian government email domain.
The tactic used by iamnotavillain mirrors a similar attack on Coinbase earlier this year, where a contractor leak exposed high-profile executives. The choice of Monero as the ransom currency is also deliberate, as it makes it nearly impossible for investigators to trace payments.