A Revolut data breach has escalated into a $3 million ransom demand, with the group behind the alleged incident threatening to sell stolen customer information if the company does not pay within 24 hours.
The group, which calls itself “iamnotavillain,” posted the demand Wednesday alongside a countdown clock, according to the Financial Times. The ransom is set at 6,000 Monero (XMR), a cryptocurrency built to make transaction details harder to trace.
At least 680 Revolut customer accounts were affected, the FT reported. The attackers also claimed they had selected targets by using blockchain analysis to identify customers with significant cryptocurrency holdings.
That detail gives the Revolut data breach a distinctly crypto-era twist. Rather than casting a random net, the group said it used information from public blockchain activity to decide which accounts were worth pursuing.
The group shared a 60-second screen recording with the FT that appeared to display some of the information it obtained. The footage reportedly included passports, driver’s licenses, photographs submitted for know-your-customer checks and transaction histories.
The Revolut Data Breach Started With a Convincing Impersonation
The incident reportedly began when attackers posed as government officials and submitted fraudulent requests for customer information. Those requests passed Revolut’s checks, leading the company to hand over records before discovering that the demands were fake.
Revolut has said its systems and customer funds were not affected. The company also said it blocked the address used in the fraudulent requests and notified the relevant government agency, law enforcement and regulators.
The company told CoinDesk that “Revolut has not received any direct contact or demand from the individuals or group making these claims.”
That leaves a sharp disconnect between the hackers’ public countdown and the bank’s account of events. The group told the FT there had been no negotiations with Revolut at the time of publication.
For now, the alleged attackers are using the threat of resale as leverage, warning that the customer data could be offered to other criminal groups if the Monero demand is not met.
