Tag: Revolut

  • Revolut Hackers Demand 6,000 XMR as Italy Opens Data Probe

    Revolut Hackers Demand 6,000 XMR as Italy Opens Data Probe

    Key Highlights

    • Italian prosecutors and anti-mafia authorities have launched an investigation after hackers allegedly compromised an Italian government email account to steal sensitive data from at least 680 Revolut customers.
    • The group “iamnotavillain” demanded 6,000 Monero (XMR), valued at approximately $3 million, threatening to sell passports, driving licenses, identity photos, and transaction histories if the ransom was not paid by a September 16 deadline.
    • Revolut confirmed no internal systems or client funds were breached, stated it had not formally received a ransom demand, and is cooperating with regulators and law enforcement while offering support to affected customers.

    Italian Authorities Investigate Government Email Compromise Linked to Revolut Data Theft

    Italian prosecutors have opened a formal investigation following allegations that cybercriminals infiltrated a government email system to obtain confidential information on hundreds of Revolut customers. According to reports from the Financial Times and Euronews, the breach enabled attackers to pose as law enforcement officials and extract sensitive personal data, including passports, driving licenses, identity photographs, and detailed transaction histories. At least 680 customer accounts are confirmed to have been compromised in the operation.

    Ransom Demand and the Role of Monero

    The threat actor, identifying as “iamnotavillain,” published a ransom demand on September 16 accompanied by a 24-hour countdown timer. The group demanded payment of 6,000 Monero (XMR), worth roughly $3 million at the time, and threatened to auction the stolen records to other criminals if the deadline passed without payment. “They said that they identified customers with a lot of crypto holdings by doing blockchain analysis.” The attackers further claimed “They said they got the records after they compromised an Italian government email system and acted as if they were law enforcement officials.” As of the latest updates, it remains unclear whether Revolut paid the ransom or if the data has been sold on underground markets.

    Revolut Denies System Breach, Confirms Customer Support Measures

    Revolut has maintained that its own infrastructure and client funds remain secure. “Revolut responded by stating they had not formally heard back from the group nor received any ransom demands.” The company added, “They confirmed that none of its internal nor client funds had been affected nor breached.” In a further statement, Revolut emphasized its cooperation with authorities: “Revolut has said that they have been working closely with other regulators and law enforcement bodies, and have also offered to help and support any of its affected customers.” The neobank has not disclosed the specific number of impacted users beyond the 680 figure cited in media reports.

    Anti-Mafia and Counterterrorism Units Join the Probe

    The investigation has escalated beyond standard cybercrime channels. Italian prosecutors are now working alongside the country’s anti-mafia and counterterrorism authorities, signaling the potential involvement of organized crime networks or the severity of the government email compromise. The participation of these specialized units underscores the gravity with which Rome is treating the infiltration of state communications infrastructure for financial fraud.

    Why This Matters

    This incident highlights a growing threat vector in which criminals target trusted government communication channels to legitimize social engineering attacks against financial institutions and their customers. By compromising an official email account, the attackers bypassed traditional verification protocols, exploiting the inherent trust placed in law enforcement correspondence. The use of Monero as the ransom currency reflects a broader trend in ransomware operations: threat actors increasingly favor privacy-preserving cryptocurrencies to obscure transaction trails. While Monero’s protocol was not breached—its privacy features functioned as designed—the case illustrates how legitimate privacy tools can be co-opted for illicit finance. For Revolut and the broader fintech sector, the episode underscores the need for robust verification mechanisms that do not rely solely on email domain authenticity, as well as proactive customer notification frameworks when third-party data exposures occur.

    Frequently Asked Questions

    How did the attackers access Revolut customer data?

    The group allegedly compromised an Italian government email account and impersonated law enforcement officials to obtain sensitive customer records, including identity documents and transaction histories, from Revolut.

    Was Revolut’s own platform hacked?

    No. Revolut confirmed that its internal systems and client funds were not breached. The data was obtained through a compromised government email account, not through a direct intrusion into Revolut’s infrastructure.

    Why did the hackers demand payment in Monero (XMR)?

    Monero’s protocol obscures transaction amounts, sender addresses, and recipient addresses by default, making it significantly harder for law enforcement to trace ransom payments compared to transparent blockchains like Bitcoin.

  • Financial Times: Revolut Hackers Lower Ransom to $3M, Set 24-Hour Deadline

    Financial Times: Revolut Hackers Lower Ransom to $3M, Set 24-Hour Deadline

    Revolut Data Breach: Hackers Demand $3 Million in Monero, Threaten to Sell 680 Customer Records

    A cybercrime group styling itself “iamnotavillain” has escalated its extortion campaign against British fintech firm Revolut, demanding 6,000 Monero (XMR) tokens—valued at approximately $3 million as of September 16, 2026—in exchange for not selling confidential data belonging to roughly 680 customers. The attackers published a 24-hour countdown timer on an external website Wednesday, setting a deadline of Thursday, September 17, 2026, according to a Financial Times investigation.

    Ransom Demand and Cryptocurrency Choice

    The ransom note specifies payment in Monero, a privacy-focused cryptocurrency selected for its anonymity and cryptographic protocols that obscure transaction trails. A 60-second screen recording provided to the Financial Times reportedly displayed compromised documents including passports, driver’s licenses, and complete banking records.

    Revolut has stated officially that it has not received any direct demand from the extortionists. A company spokesperson confirmed that core infrastructure and primary databases suffered no unauthorized access, suggesting the breach may be limited to a specific compliance-related dataset.

    Breach Vector: Government Domain Impersonation

    The security incident originated from a fraudulent information request sent from a legitimate government domain. Compliance staff processed the request before identifying the identity spoofing, allowing the attackers to extract sensitive customer information. Revolut has since blocked the compromised domain and formally alerted law enforcement authorities.

    Scope of Compromised Data

    Official company disclosures indicate the leaked dataset includes:

    • Full names, residential addresses, and phone numbers
    • Identity verification photographs
    • IBAN numbers and account opening dates
    • Account statements referencing Bitcoin transfers

    The attackers told the Financial Times they used on-chain analytics to specifically target customers with significant digital asset holdings. Prior reporting by on-chain investigator ZachXBT suggests the affected accounts correspond to high-net-worth profiles, indicating a highly targeted operation rather than a broad data dump.

    Regulatory Response and Timeline

    The UK Information Commissioner’s Office (ICO) maintains an open formal investigation into the matter. UK and European Union regulators have scheduled supervisory hearings on the incident toward the end of the third quarter of 2026, signaling heightened regulatory scrutiny of fintech data protection practices.

    The extortionists’ ultimatum expires Thursday, September 17, 2026. Whether Revolut engages with the demand or relies on law enforcement intervention remains unresolved as the countdown continues.

  • Revolut Attackers Threaten Daily Customer Data Leaks

    Revolut Attackers Threaten Daily Customer Data Leaks

    Threat actors who obtained sensitive Revolut customer information appear to have begun posting the data online and are threatening to release more information daily until the fintech company pays.

    High-Profile Individuals Among Leaked Data

    The newly leaked information reportedly includes selfies and copies of identity documents belonging to tennis player Alexander Shevchenko and Gamdom CEO Felix Römer, according to an X post from International Cyber Digest on Sunday.

    Attackers Issue Daily Release Threat

    “We’re going to start releasing more and more data everyday until revolut pays for leaking their customers,” the attackers reportedly said on Telegram. Cointelegraph reached out to Revolut and Römer for comment.

    Identity Theft Risks Escalate

    The exposed identity documents and facial-verification images could increase the risk of identity theft. Revolut on Friday told customers the leaked data also includes customers’ full name, date of birth, occupation, contact information, account statements and full transaction history, including records of Bitcoin transactions.

    Breach Origin: Government Email Impersonation

    Revolut told Cointelegraph on Saturday that the customer data was leaked due to a “sophisticated external impersonation scam” in which the attacker used an email address from a legitimate government agency domain email to submit fraudulent requests for information.

    Revolut later told Cointelegraph the breach affected a “⁠limited number” of customers, and its systems and customer funds are unaffected.

    Related: Revolut says customer data exposed through fake government email

  • Revolut Disclosed Customer Bitcoin Records Following Unauthorized Government Request, Report Says

    Revolut Disclosed Customer Bitcoin Records Following Unauthorized Government Request, Report Says

    A number of Revolut customers have reported receiving notifications that their personal and financial data — including Bitcoin transaction histories — was disclosed in response to a government request now believed to be fraudulent.

    Fraudulent Request Used Legitimate-Looking Credentials

    According to an email shared by onchain investigator ZachXBT, the request originated from an unauthorized email account that nevertheless used a government agency’s official domain and carried valid domain authentication credentials. The convincing appearance of the request may have led Revolut to process it without detecting the deception.

    Scope of Exposed Data

    The disclosed information is extensive. Personal details include customers’ full names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers. Identity and verification records — such as passport or driver’s license copies and verification selfies — were also released.

    On the financial side, the data covers account statements, IBANs, withdrawal records, and full transaction histories, including Bitcoin activity. The email specified that biometric facial telemetry data was not shared.

    Experts Warn of Targeted Attack on High-Net-Worth Users

    Security experts suggest Revolut may have failed to recognize the fraudulent nature of the request before releasing customer information. “While the incident is likely limited in size it seems to have been targeted at high net worth users,” ZachXBT said.

    Revolut has not yet commented publicly on the reported data exposure.