Markets World Tech USA · World
Nikkei 225
64,175.56
+252.56   +0.40%
Live
Hang Seng
24,713.78
-203.82   -0.82%
At close
Shanghai
3,891.60
+6.27   +0.16%
Pre-market
ASX 200
8,731.30
+34.80   +0.40%
Live
Nifty 50
23,217.60
-180.50   -0.77%
At close

Crypto

Revolut hackers demand $3 million in Monero, threaten to sell customer data

· CoinDesk

The group gave Revolut 24 hours to pay and said it targeted customers with significant crypto holdings.

  • Hackers are demanding $3 million in monero (XMR) within 24 hours or threatening to sell stolen Revolut customer data to other criminal groups.
  • At least 680 customer accounts were affected, with exposed data reportedly including identity documents and transaction histories.
  • The hackers told the FT they used blockchain analysis to identify Revolut accounts with significant crypto holdings.

The hackers behind a data breach at Revolut are demanding $3 million worth of monero (XMR) within 24 hours, threatening to sell the stolen customer data to other criminal groups if the bank refuses to pay, according to the Financial Times.

The group, which calls itself “iamnotavillain,” posted the demand Wednesday alongside a countdown clock, the FT reported. It asked Revolut to send 6,000 XMR, a cryptocurrency designed to obscure transaction details.

At least 680 Revolut customer accounts were affected by the breach, according to the report.

The hackers told the FT they chose their targets using blockchain analysis to find Revolut accounts with significant crypto holdings.

The group sent the FT a 60-second screen recording that appeared to show some of the data it obtained. The video included passports, driving licences, photos used for know-your-customer checks and transaction histories, according to the newspaper.

The breach came after attackers posed as government officials and sent requests for information that passed Revolut’s checks. Revolut handed over customer records before discovering the requests were fraudulent, according to notices previously sent to affected customers.

Revolut previously told CoinDesk that it blocked the address used in the requests and notified the relevant government agency, law enforcement and regulators. The company said its systems and customer funds were unaffected.

The hackers told the FT there had been no negotiations with Revolut at the time of publication.

Revolut did not respond to CoinDesk’s request for comment by publication.

As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.