Revolut Hit with $3M Monero Ransom Demand After Email Scam
Revolut, a UK-based fintech company, is facing a severe cyber threat after hackers demanded 6,000 XMR (Monero) worth approximately $3 million. The attackers claim to have accessed sensitive customer data and will sell it to other criminal groups if the ransom isn't paid within 24 hours.
The public ultimatum, published on a website with a countdown timer, targets around 680 affected customers. Revolut confirmed that an unauthorized party used a legitimate government agency email domain to submit fraudulent information requests, exposing a weakness in how privileged requests for customer data are authenticated.
Regulatory scrutiny is already underway, with the UK's Information Commissioner's Office and the Financial Conduct Authority investigating the incident. The attackers did not need to compromise Revolut's banking infrastructure; instead, they exploited a legitimate government email domain to access sensitive information.