Fraudulent Requests and Targeted Data Compromise
Financial platform Revolut compromised customer records after responding to fraudulent law enforcement information requests over several months 3. Attackers sent the inquiries using a compromised Italian government email system that possessed valid authentication credentials 3. Because the communications successfully bypassed standard internal security checks, platform operators handed over sensitive records before recognizing the fraudulent nature of the requests 13. Revolut subsequently blocked the originating contact address and informed law enforcement, relevant regulators, and the impacted government agency 1.
The breach impacted at least 680 customer accounts 13. Security investigator ZachXBT noted that the incident appeared designed to compromise high-net-worth users 3. The perpetrator group explained to journalists that it initially conducted on-chain blockchain analysis to spot public addresses tied to substantial cryptocurrency balances 13. After identifying these high-value account holders on-chain, the group targeted their associated centralized profiles to extract personal information 13.
Exfiltrated data contained extensive personal identification and financial records 3. The stolen files encompassed full customer names, birth dates, home addresses, occupations, driver's licenses, and passport copies 3. Additionally, the leak exposed know-your-customer self-portrait images, account statements containing IBAN details, wallet references, withdrawal records, and complete transaction histories 3. Attackers verified the possession of these files by transmitting a 60-second screen recording to news media 13.
Ransom Demand and Monero Extortion Details
An extortion entity operating under the handle "iamnotavillain" created a dedicated website displaying a 24-hour countdown timer to demand payment 13. The group demanded 6,000 Monero tokens, valued at approximately $3 million 13. The extortion site warned that "all the data will be sold, and the blood will be on your hands" if payment conditions were not met 3. On September 16, 2026, initial reports detailed that the hackers threatened to sell the identity documentation to third-party criminal organizations 13.
The extortionists specifically demanded payment in Monero, a privacy-focused cryptocurrency that utilizes stealth addresses and ring signatures to obscure payment details 3. Major cryptocurrency exchanges such as Coinbase, Kraken, and Binance have delisted the token from their trading platforms 3. According to analytics firm TRM Labs, extortion groups frequently request Monero or offer discounts for its use, though Bitcoin remains the primary asset for extortion settlements because it is far easier to acquire, move, and convert at scale 3.
Revolut stated that it had not received direct demands or communications from the extortion group as of September 16, 2026 13. The hackers told the Financial Times that there had been no negotiations with Revolut at the time of publication 1. Furthermore, Revolut reiterated that customer monetary balances and internal operating systems remained completely unaffected by the security breach 13.
Centralized Identity Storage and Physical Security Risks
The exposure of verified physical identities alongside known cryptocurrency balances presents distinct physical safety hazards 23. Observers note that linking real-world addresses, legal names, and face images to visible public blockchain balances correlates directly with physical extortion risks, such as physical mail demanding bitcoin 2 or violent wrench attacks 3. Unlike compromised private keys or lost tokens, compromised personal identification data cannot be revoked, rotated, or replaced easily 2.
Data breaches at central repositories highlight ongoing vulnerabilities across financial and hardware services 2. For instance, a separate hardware wallet leak from 2020 resulted in physical extortion letters arriving at customer home addresses six years later 2. In another instance, hardware vendor Trezor confirmed that approximately 67,000 customer records were exposed through an external shipping partner, while another leak exposed roughly 200,000 records containing government identification numbers alongside verified wallet addresses 2.
Industry analysis suggests that centralized know-your-customer records create high-value targets for attackers 2. When entities retain static records of sensitive personal identity documents, servers become concentrated data stores 2. Alternative verification models emphasize minimal disclosure, where platforms confirm a user's regulatory eligibility without retaining persistent copies of personal documents or faces 2.
Formal Disclosures and Unresolved Elements
Revolut described the total number of impacted accounts as limited and confirmed that operational infrastructure was not breached 3. Platform administrators notified affected users directly regarding the unauthorized disclosure of their information 13. However, company officials declined to publicly identify the specific Italian government agency whose email domain was compromised in the attack 3.
It remains unconfirmed whether any portion of the stolen dataset has been transferred or sold to third parties following the expiration of the extortion deadline 13. Furthermore, full details regarding how attackers obtained authenticated access to the government email system remain under investigation by authorities 13.
What is not yet established
- Whether Revolut customer data has been sold or distributed to third parties following the ransom deadline.
- The specific Italian government agency whose authenticated email domain was compromised to issue fraudulent requests.
- The exact identities or location of the individuals operating under the alias 'iamnotavillain'.
Frequently asked questions
How did attackers access Revolut customer records?
Attackers submitted fraudulent information requests using a compromised Italian government email address that held valid authentication, leading Revolut to fulfill the requests before discovering the fraud 13.
Sources
- CoinDesk — Revolut hackers demand $3 million in Monero, threaten to sell customer data (2026-09-16) https://www.coindesk.com/markets/2026/09/16/revolut-hackers-demand-usd3-million-in-monero-threaten-to-sell-customer-data
- CoinDesk — A stolen coin can be returned. A leaked identity cannot. (2026-09-16) https://www.coindesk.com/opinion/2026/09/16/a-stolen-coin-can-be-returned-a-leaked-identity-cannot
- Decrypt — Revolut Hackers Demand $3M Monero Ransom, Threaten to Sell Customer Data: Report (2026-09-17) https://decrypt.co/378472/revolut-hackers-demand-3m-monero-ransom-threaten-to-sell-customer-data-report
This brief is for information and education. It is not financial advice or a recommendation to buy or sell.