MoneroXMR, coin
DisputedHack

Group Demands $3M in Monero From Revolut After Data Breach via Fake Government Emails

A group calling itself iamnotavillain is demanding 6,000 XMR (about $3 million) from Revolut within 24 hours, threatening to sell stolen customer data, which Revolut says it has not been contacted about.

Why it matters

The breach shows attackers bypassing Revolut's security by impersonating a government agency rather than compromising its core systems, prompting scrutiny from UK regulators over how the fintech authenticates data requests from law enforcement.

Where the sources disagree

Size and asset of the ransom demand

6,000 XMR (~$3 million)

Crypto News Flash, Decrypt, Protos

10,000 BTC (over $760 million), per Coin Bureau, unconfirmed

Protos

Crypto News Flash, Decrypt and Protos report a 6,000 XMR (~$3 million) demand from the group iamnotavillain, while Protos notes Coin Bureau earlier reported a separate, unconfirmed 10,000 BTC (over $760 million) demand from an unidentified group, and it is unclear if it is the same attackers.

Key facts

A group calling itself iamnotavillain demanded 6,000 XMR, about $3 million, from Revolut within 24 hours

6,000 XMRDisputed figureReported by Crypto News Flash

Revolut said it has received no direct contact or ransom demand from the attackers

Reported by Crypto News Flash

Revolut confirmed on September 12 that an unauthorized party used a legitimate government agency email domain to submit fraudulent data requests

Reported by Crypto News Flash

The attackers used access to an Italian government email account to pose as law enforcement and bypass Revolut's security checks

Reported by Protos

A source familiar with the attack told Reuters around 680 customers were affected

680Reported by Crypto News Flash

The group told the Financial Times it used blockchain analysis to identify Revolut customers with large crypto holdings before targeting them

Reported by Decrypt

Coin Bureau previously reported an unconfirmed demand of 10,000 BTC, worth over $760 million, from attackers whose identity was never revealed

10,000 BTCDisputed figureReported by Protos

Reuters reported that the attack did not impact Revolut's core infrastructure, databases or customer accounts

Reported by Protos

What happened

A group calling itself 'iamnotavillain' published a public ransom demand for 6,000 Monero, worth about $3 million, giving Revolut 24 hours to pay or have stolen customer data sold to other criminals, according to Crypto News Flash, Decrypt and Protos, all citing the Financial Times. Revolut confirmed on September 12 that an unauthorized party used a legitimate Italian government email domain to submit fraudulent data requests, which it says did not affect its core banking infrastructure, databases or customer accounts. Reuters and Revolut both say the company has had no direct contact or ransom demand from the attackers, meaning the threat remains public rather than delivered privately. Decrypt reports the group told the Financial Times it used blockchain analysis to identify Revolut customers with large crypto holdings before targeting their accounts. Protos notes that Coin Bureau had earlier reported a separate, unconfirmed demand of 10,000 BTC (over $760 million) from attackers whose identity was never disclosed, and it is unclear whether the same group is behind both claims. Reuters, cited by Protos, says a source familiar with the matter put the number of affected customers at around 680.

How the story developed

  1. Official statement

    Revolut confirms fraudulent government-email data requests

    Revolut said an unauthorized party used a legitimate government agency email domain to submit fraudulent requests, and it blocked the address and alerted authorities.

    Crypto News Flash

  2. First report

    First report by Crypto News Flash

    Revolut Faces 6,000 XMR Monero Extortion Demand Following Legal Email Scam

    Crypto News Flash

  3. Update

    iamnotavillain publishes public ransom demand

    The group launched a ransom website demanding 6,000 XMR (~$3 million) with a 24-hour countdown timer.

    Crypto News Flash

  4. Independent corroboration

    Independently corroborated by Decrypt

    Revolut Hackers Demand $3M Monero Ransom, Threaten to Sell Customer Data: Report

    Decrypt

  5. Update

    Decrypt reports blockchain-analysis targeting claim via Financial Times

    The group told the Financial Times it used blockchain analysis to pick out Revolut customers with large crypto holdings.

    Decrypt

  6. Update

    Protos reports Reuters confirmation of no contact and affected customer count

    Reuters reported Revolut had no contact with attackers and a source put affected customers at around 680.

    Protos

How coverage built up

Independent sources over time, counted the way the consensus panel counts them: a republication of a wire story does not move the line.

17 Sept, 09:153 independent sources17 Sept, 13:10
  • 17 Sept 2026, 09:15 UTC: Crypto News Flash 1 independent source, 1 reports
  • 17 Sept 2026, 12:53 UTC: Decrypt 2 independent sources, 2 reports
  • 17 Sept 2026, 13:10 UTC: Protos 3 independent sources, 3 reports

Affected entities

Also mentioned: Financial Conduct Authority, India

Original sources

PublisherReportRolePublished
Crypto News Flash
Crypto media
Revolut Faces 6,000 XMR Monero Extortion Demand Following Legal Email ScamOriginal
Decrypt
Crypto media
Revolut Hackers Demand $3M Monero Ransom, Threaten to Sell Customer Data: ReportIndependent
Protos
Crypto media
Revolut faces $3M ransom demand after data breach, reportIndependent