Revolut Hackers Demand $3M Ransom for Confidential Customer Data
A group of hackers, known as 'iamnotavillain', has breached Revolut's security and is demanding a ransom in exchange for not selling confidential customer information. The attackers claim to have sensitive data belonging to approximately 680 customers, including names, residential addresses, phone numbers, identity verification photographs, IBAN numbers, account opening dates, and account statements referencing Bitcoin transfers.
The hackers used on-chain analytics to target high-net-worth customers with significant digital asset holdings. The group is demanding 6,000 Monero (XMR) tokens, equivalent to around $3 million as of September 16, 2026. This reduced ransom amount was set after the attackers published a 24-hour countdown clock, threatening to sell the files if the demand is not met.
Revolut has stated that its core infrastructure and primary databases were not compromised in the breach. The company blocked the domain used for the deception and notified law enforcement authorities. An open formal investigation into the matter is being maintained by the UK Information Commissioner's Office (ICO).