Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
About
CLAY TRIBUNE.
ShopCartAccount
Advertisement

Revolut Hackers Demand $3M Monero Ransom, Threaten to Sell Customer Data: Report

Revolut hacked: hackers demand $3M ransom in Monero or will sell stolen customer data, per the Financial Times.

By mitch·5 min read
A shadowy hacker silhouette looms over a cracked digital vault glowing with binary code.

Revolut faces a deadline from a hacking group demanding $3 million in Monero ransom, with the threat that if the payment is not made within 24 hours, the attackers will sell hundreds of customers’ identity documents and transaction records to other criminals, per the Financial Times. The demand follows days after Revolut acknowledged a breach linked to a compromised Italian government email system.

Wednesday, a website set up by the group carried a demand asking for “6,000 XMR / $3,000,000”, with a warning that failure to meet it would bring “all the data will be sold, and the blood will be on your hands.”. The group claims it relied on blockchain analysis to identify customers holding substantial crypto assets.

The Ransom Demands

The attackers are demanding payment in Monero, which hides who sends and receives funds along with the transaction amounts through ring signatures and stealth addresses. That currency has been removed from trading on several major exchanges, among them Binance, Coinbase and Kraken.

Advertisement

TRM Labs reports that extortion groups ask for Monero and occasionally cut their demands for victims who pay in it. Most ransoms are still settled in Bitcoin, which TRM describes as “far easier to acquire, move, and convert at scale.”.

The group has made its intentions clear: if Revolut fails to pay, the stolen data will be handed over to other criminals. This is not a vague threat. The hackers have already provided proof to the FT by showing a screen recording of the files.

How the Victims Were Chosen

The distinguishing feature of this attack is how the targets were selected. According to the FT, the group said it began with blockchain analysis, identifying Revolut customers whose on-chain activity pointed to significant holdings, before moving against those particular accounts.

Blockchain investigator ZachXBT, who first circulated the customer notification, said the breach appeared “targeted at high net worth users.” That matches the group’s account of how it picked them.

The profile at the center of the increase in violent wrench attacks on known crypto owners combines verified identity, home address and proven holdings. Hackers already knew which people had money before they ever laid hands on them.

The Breach Details

The payments firm Revolut gave up its own data after receiving requests from an official government email address that included proper authentication. The company has called it “a sophisticated external impersonation scam.”.

A hacked Italian government email system was used to make the requests, according to the FT, which says they spanned several months and involved at least 680 accounts.

The stolen data was extensive:

  • Names, dates of birth, occupations, home addresses
  • Passport or driving licence copies, selfies customers submit for verification
  • Account statements with IBANs and wallet references
  • Withdrawal records and full transaction histories

The hackers have since shown the FT a screen recording of the files. Revolut said on Wednesday evening it “has not received any direct contact or demand from the individuals or group making these claims.”

Revolut’s Response So Far

Revolut has called the number of affected customers “limited.” It says funds and systems were untouched and has declined to name the agency involved.

What stands out about the company’s statement is what it fails to include. The firm made no comment on the FT’s reported figure of 680 accounts. Nor did it address whether the agency in question operates in Italy.

What This Means for Revolut

Revolut finds itself in an uncharted position. A hacking group has broken into its systems, taken data from hundreds of customers, and now demands payment in a coin that major exchanges no longer trade. The company confronts a familiar extortion problem: it can pay and establish a precedent, or refuse and allow its customers’ identities to spread.

Roughly $3 million XMR is what the group demands. The deadline is 24 hours from the moment the demand was made.

The company has not confirmed the threat beyond its standard statement, so Revolut remains caught between the hacker group and the data it holds.

Timeline of the Incident

Date Event
Months prior Information requests arrive via compromised Italian government email system
Wednesday Group posts demand for 6,000 XMR ($3 million) on dedicated website
Wednesday evening Revolut issues statement saying it has received no direct contact

Days after Revolut acknowledged the hack, the company now faces a ransom deadline. The admission came quickly, and the window for responding to the specific demand is measured in days.

The Profile Behind the Attack

The approach used to find victims stands out. The group first examined blockchain activity, next singled out users with substantial crypto holdings, and finally went after those particular profiles.

The profile matches the same one behind the violent wrench attacks on known crypto owners. It features verified identity, home address, and proven holdings.

The people behind the attacks know which individuals hold funds. They also know where those resources can be found. Furthermore, they are ready to put what they have taken up for sale.

The Cost of Compromise

What happened at Revolut is more than a simple data leak. It shows how information travels when it is kept in systems that can be broken into. Governments, companies and people all put sensitive material into these systems, and the effects reach wide when those systems fail.

What was taken goes beyond a simple password reset; it amounts to a lasting breach. The hackers have captured records containing passports, driving licences, home addresses and transaction histories. Each of these items has been recorded.

The choice put before Revolut is plain: either pay up, or let the data be made public. The company has 24 hours to make its decision.

This tale revolves around data, trust, and the expense of keeping money on the web. Revolut has become the newest firm to discover that lesson through bitter experience. The attackers now possess the records. Time is running out.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.