BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

Crypto Hack News: Revolut Hackers Demand $3M Monero Ransom Payment

Revolut Faces New Crypto Hack News After Customer Records Are Stolen A fresh wave of crypto hack news broke this week after a group calling itself "iamnotavillain" claimed responsibility for

AnonymousCryptoCompass newsroom
September 17, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for policy coverage.

Revolut Faces New Crypto Hack News After Customer Records Are Stolen

A fresh wave of crypto hack news broke this week after a group calling itself "iamnotavillain" claimed responsibility for stealing customer records from Revolut. 

The attackers say they now hold files belonging to about 680 accounts and are demanding payment to stop the data from being sold. 

The story adds Revolut to a growing list of fintech firms caught up in extortion attempts tied to crypto holders.

Hackers Demand 6,000 XMR Within 24 Hours

According to the Financial Times, the group behind this crypto hack news event is asking for 6,000 Monero, worth roughly three million dollars at current rates. 

A countdown clock was posted on the attackers' site, giving the London-based fintech only 24 hours to respond before the stolen files are offered to other criminal groups. 

What Customer Data Was Reportedly Exposed

The attackers shared a short screen recording with reporters that appeared to show sensitive material taken during the breach. Reported items include:

  • Passport scans and driving license images

  • Photos submitted for identity verification checks

  • Full transaction histories, including Bitcoin activity

  • Bank account details linked to affected users

The group told reporters it used blockchain analysis to pick targets, focusing on accounts that showed signs of large crypto holdings. 

That detail has turned this incident into one of the more closely watched pieces of Crypto Hack News this year, since it points to a method of using public transaction data to find high-value victims.

Official Financial Times Report

Source: Financial Times Report

How the Fraudulent Request Slipped Past Checks

Revolut says the breach did not come from a direct attack on its core systems. Instead, an unauthorized party used an email account tied to a legitimate government domain to send requests for customer records. 

Those requests passed the fintech's standard verification steps before staff realized the emails were fraudulent. The company states that customer funds and primary databases were not touched.

Key Details at a Glance

Detail

Reported Figure

Ransom demand

6,000 XMR (about $3 million)

Payment deadline

24 hours

Accounts affected

Around 680

Attacker group

iamnotavillain

Why Monero Was Chosen for the Ransom

Monero was selected because its protocol is built to hide the sender, receiver, and amount in every transaction, making it far harder for investigators to trace than Bitcoin. 

Coverage of this Crypto Hack News episode notes that switching from Bitcoin to Monero could make any payment much harder to follow on-chain, a factor that has made the coin a recurring choice in extortion cases.

BSCN X Post showing update

Source: BSCN X Post

Company Response and Regulatory Attention

A Revolut spokesperson said the firm has not received a direct ransom demand and that the incident is being treated as an external impersonation scam rather than a system-wide compromise. 

The fintech has notified law enforcement and the relevant government agency whose domain was misused, and it blocked the address linked to the fraudulent requests. 

UK regulators are reported to be reviewing the case, and the episode arrives shortly after Revolut secured conditional approval to operate as a national bank, adding extra scrutiny to how it handles sensitive KYC records.

Conclusion

For now, no negotiation between Revolut and the attackers has been confirmed, and the fintech has not said whether it intends to pay. 

The wider Crypto Hack News angle here is a reminder that even firms with strong core security can be exposed through a single trusted communication channel and that users with visible on-chain wealth remain a preferred target for groups running this kind of extortion campaign.

YMYL Disclaimer: This article is for informational purposes only and does not constitute financial, legal, or investment advice. Readers should verify details with official sources before acting on any information.