Crypto: Hackers demand $3 million in Monero from Revolut
Summarize this article with:

Revolut faces new pressure after the data leak revealed a few days earlier. A group calling itself iamnotavillain is now demanding 6,000 XMR. It’s worth around $3 million, and threatens to sell the stolen information if the fintech doesn’t pay. The attackers set a deadline of 24 hours. Around 680 customers, including several significant crypto holders, would be affected. Revolut claims for its part that it has not received any requests directly.

Cybersecurity team faces crypto ransom demand from 3M in Monero.

In brief

  • The attackers demand 6,000 XMR, or around $3 million.
  • Around 680 Revolut customers are believed to be affected by the leak.
  • Revolut assures that its core systems and customer funds have not been hacked.

Attackers are now demanding 6,000 XMR

The deal comes at a bad time for Revolut, which is rapidly expanding its digital assets business. Tremplin.io detailed again this week the expansion of Revolut in crypto, between stablecoin, trading and payments.

This time, fintech is mainly facing a matter linked to personal data. The iamnotavillain group published its ultimatum on Wednesday on a website accompanied by a countdown. The hackers are demanding 6,000 Monero and say they will pass the records on to other criminal groups if Revolut does not pay within 24 hours.

A first request for 10,000 BTC had previously circulated on Telegram. The authors of the current ultimatum, however, say that this sum came from an impostor or a former associate.

The choice of Monero is less surprising. Unlike bitcoin, whose transactions are publicly visible on the blockchain, XMR crypto is designed to hide more information about transfers. Revolut claims to have had no direct contact with the group and has not received any ransom demands through its own channels.

Your first cryptos with KuCoin
This link uses an affiliate program

Hackers would not have penetrated Revolut’s systems

The leak would not have arisen from a classic intrusion. Revolut confirmed on September 12 that it had passed sensitive information to an unauthorized person after receiving false requests from a legitimate government email domain. Revolut assures that no compromise has affected its systems or its customers’ funds.

The attackers allegedly exploited the Italian PEC-certified email system. By posing as law enforcement representatives, they allegedly sent targeted requests concerning certain customers for several months.

Among the information exposed would be dates of birth, postal and email addresses, telephone numbers as well as copies of passports and driving licenses. Transaction histories and data related to crypto movements would also be part of the files obtained.

According to the information reportedaround 680 people would be affected, mainly in France and Switzerland, but also in several dozen other European countries. The attackers say they used blockchain analysis to spot clients with significant digital asset activity.

The file recalls another recent case. In February, a former Revolut employee was already accused of using KYC data to pressure a crypto investor. Two different stories, with the same type of sensitive information at the center.

Monero crypto returns to the heart of an extortion case

Hackers are not asking for dollars, or even bitcoins. They want XMR crypto. Monero was designed with privacy as its core function. Several cryptographic mechanisms hide sending and receiving addresses as well as the amounts transferred. This architecture explains why the token regularly appears in ransom or payment files that their authors seek to make more difficult to follow.

This does not mean, however, that Monero offers perfect invisibility. Specialized companies have been working for several years on methods to reduce anonymity.

Tremplin.io notably reported in 2024 that certain Monero transactions could be tracked through the analysis of nodes and IP addresses. In the Revolut affair, the most sensitive point remains elsewhere: personal data. A passport, full address, verification photos and financial history can be put to malicious use long after an ultimatum has expired. Revolut says it has blocked the address used for the false requests and alerted authorities, financial regulators and data protection agencies. At this stage, there is no evidence of theft of customer funds. The request is now public: 6,000 XMR and 24 hours.

Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.

Similar Posts