Group Demands $3M in Monero From Revolut After Data Breach via Fake Government Emails
A group calling itself iamnotavillain is demanding 6,000 XMR (about $3 million) from Revolut within 24 hours, threatening to sell stolen customer data, which Revolut says it has not been contacted about.
Why it matters
The breach shows attackers bypassing Revolut's security by impersonating a government agency rather than compromising its core systems, prompting scrutiny from UK regulators over how the fintech authenticates data requests from law enforcement.
Where the sources disagree
Size and asset of the ransom demand
6,000 XMR (~$3 million)
Crypto News Flash, Decrypt, Protos
10,000 BTC (over $760 million), per Coin Bureau, unconfirmed
Protos
Crypto News Flash, Decrypt and Protos report a 6,000 XMR (~$3 million) demand from the group iamnotavillain, while Protos notes Coin Bureau earlier reported a separate, unconfirmed 10,000 BTC (over $760 million) demand from an unidentified group, and it is unclear if it is the same attackers.
Key facts
A group calling itself iamnotavillain demanded 6,000 XMR, about $3 million, from Revolut within 24 hours
6,000 XMRDisputed figureReported by Crypto News Flash
Revolut said it has received no direct contact or ransom demand from the attackers
Reported by Crypto News Flash
Revolut confirmed on September 12 that an unauthorized party used a legitimate government agency email domain to submit fraudulent data requests
Reported by Crypto News Flash
The attackers used access to an Italian government email account to pose as law enforcement and bypass Revolut's security checks
Reported by Protos
A source familiar with the attack told Reuters around 680 customers were affected
680Reported by Crypto News Flash
The group told the Financial Times it used blockchain analysis to identify Revolut customers with large crypto holdings before targeting them
Reported by Decrypt
Coin Bureau previously reported an unconfirmed demand of 10,000 BTC, worth over $760 million, from attackers whose identity was never revealed
10,000 BTCDisputed figureReported by Protos
Reuters reported that the attack did not impact Revolut's core infrastructure, databases or customer accounts
Reported by Protos
What happened
A group calling itself 'iamnotavillain' published a public ransom demand for 6,000 Monero, worth about $3 million, giving Revolut 24 hours to pay or have stolen customer data sold to other criminals, according to Crypto News Flash, Decrypt and Protos, all citing the Financial Times. Revolut confirmed on September 12 that an unauthorized party used a legitimate Italian government email domain to submit fraudulent data requests, which it says did not affect its core banking infrastructure, databases or customer accounts. Reuters and Revolut both say the company has had no direct contact or ransom demand from the attackers, meaning the threat remains public rather than delivered privately. Decrypt reports the group told the Financial Times it used blockchain analysis to identify Revolut customers with large crypto holdings before targeting their accounts. Protos notes that Coin Bureau had earlier reported a separate, unconfirmed demand of 10,000 BTC (over $760 million) from attackers whose identity was never disclosed, and it is unclear whether the same group is behind both claims. Reuters, cited by Protos, says a source familiar with the matter put the number of affected customers at around 680.
How the story developed
- Official statement
Revolut confirms fraudulent government-email data requests
Revolut said an unauthorized party used a legitimate government agency email domain to submit fraudulent requests, and it blocked the address and alerted authorities.
- First report
First report by Crypto News Flash
Revolut Faces 6,000 XMR Monero Extortion Demand Following Legal Email Scam
- Update
iamnotavillain publishes public ransom demand
The group launched a ransom website demanding 6,000 XMR (~$3 million) with a 24-hour countdown timer.
- Independent corroboration
Independently corroborated by Decrypt
Revolut Hackers Demand $3M Monero Ransom, Threaten to Sell Customer Data: Report
- Update
Decrypt reports blockchain-analysis targeting claim via Financial Times
The group told the Financial Times it used blockchain analysis to pick out Revolut customers with large crypto holdings.
- Update
Protos reports Reuters confirmation of no contact and affected customer count
Reuters reported Revolut had no contact with attackers and a source put affected customers at around 680.
How coverage built up
Independent sources over time, counted the way the consensus panel counts them: a republication of a wire story does not move the line.
- 17 Sept 2026, 09:15 UTC: Crypto News Flash — 1 independent source, 1 reports
- 17 Sept 2026, 12:53 UTC: Decrypt — 2 independent sources, 2 reports
- 17 Sept 2026, 13:10 UTC: Protos — 3 independent sources, 3 reports
Affected entities
Also mentioned: Financial Conduct Authority, India
Original sources
| Publisher | Report | Role | Published |
|---|---|---|---|
| Crypto News Flash Crypto media | Revolut Faces 6,000 XMR Monero Extortion Demand Following Legal Email Scam | Original | |
| Decrypt Crypto media | Revolut Hackers Demand $3M Monero Ransom, Threaten to Sell Customer Data: Report | Independent | |
| Protos Crypto media | Revolut faces $3M ransom demand after data breach, report | Independent |