Revolut Faces $3M Monero Ransom Demand Over Stolen Customer Data

Revolut is facing a $3 million ransom demand in Monero (XMR) from a group claiming to have obtained customer data in an alleged breach. The group has given the company 24 hours to pay 6,000 XMR and threatened to sell the information to other criminal groups if Revolut refuses.

The group, which uses the name “iamnotavillain,” published the demand on Wednesday alongside a countdown timer, according to the Financial Times.

Revolut said it has not been contacted directly by the people making the claims. “Revolut has not received any direct contact or demand from the individuals or group making these claims,” a company spokesperson told CoinDesk.

The reported incident affected at least 680 customer accounts. The attackers told the FT that they relied on blockchain analysis to identify Revolut users whose accounts held significant cryptocurrency balances.

The group also sent the FT a 60-second screen recording that allegedly showed some of the customer information it had accessed. According to the newspaper, the footage contained passports, driver’s licenses, photos submitted for know-your-customer checks and transaction histories.

The breach reportedly followed a social-engineering attack in which the perpetrators impersonated government officials and submitted requests for customer information. The requests passed Revolut’s verification procedures, leading the company to provide customer records before discovering that the requests were fraudulent, according to notices previously issued to affected users.

Revolut previously told CoinDesk that it had blocked the address used in the fraudulent requests and alerted the relevant government agency, law enforcement authorities and regulators. The company said its systems and customer funds were not affected.

The group told the FT that no negotiations with Revolut had taken place when the newspaper published its report.