Skip to content
September 22, 2026
Nifty 50+0.62%
Sensex+0.55%
S&P 500-0.18%
Crypto

Revolut hackers demand $3 million as breach exposes crypto holders’ data

Hackers demanding a $3 million Monero ransom have exposed customer records and cryptocurrency transaction histories from a targeted Revolut data breach.

Revolut hackers demand $3 million as breach exposes crypto holders’ data

The attackers who tricked Revolut into handing over customer records are demanding a $3 million ransom to keep the information secret, the Financial Times (FT) reported. The exposed files contain identity documents, residential addresses, and transaction histories tied to accounts with substantial cryptocurrency holdings.

Beyond the ransom demand, the breach carries other severe implications. The leaked data has the potential to link transparent on-chain wealth directly to individual identities. For Revolut, which recently secured conditional approval to establish a national bank, the security lapse sparks a broader inquiry regarding how centralized financial institutions safeguard their know-your-customer (KYC) records.

A Monero ransom and a threat to leak

Reporting from the Financial Times indicates that the group, identifying themselves as “iamnotavillain,” has requested $3 million paid in Monero while threatening to publish the files should Revolut fail to comply. Meanwhile, Reuters stated that Revolut has not received any ransom demands or direct communications from the perpetrators. One insider referenced by the news service noted that roughly 680 customer records were breached, though Revolut has declined to provide exact figures, describing the volume of impacted users merely as “limited.”

Additional reporting by the FT states that the hackers also asserted they compromised an Italian government email system and conducted blockchain analysis to pinpoint Revolut customers possessing significant amounts of digital assets. Revolut has not independently verified these claims.

How the records left Revolut

Revolut maintained that its core infrastructure and user funds remained secure throughout the incident. Instead, the breach occurred when a legitimate government agency domain’s email account was used to transmit fraudulent information requests. The firm characterized the event as a “sophisticated external impersonation scam,” noting that the suspicious email address was blocked promptly upon discovery.

The compromised data encompassed full names, birth dates, home addresses, phone numbers, identification documents, verification selfies, bank statements, and transaction logs. Furthermore, crypto publication The Block noted that former Mt. Gox executive Mark Karpeles confirmed he was a victim, sharing a notification from Revolut indicating that specifics concerning his Bitcoin transactions had been exposed.

“Revolut customers were targeted in a fraudulent emergency data request sent via an email at a ‘government agency.’” — Mark Karpelès

On-chain investigator ZachXBT observed that the breach appeared calculated rather than indiscriminate.

“While the incident is likely limited in size it seems to have been targeted at high net worth users.” — ZachXBT

Why exposed KYC becomes a safety problem

When a residential address is combined with proof of substantial crypto holdings, a digital data breach rapidly escalates into a physical security risk. Data from Chainalysis shows that numerous violent crypto-related crimes are planned in advance, with targets identified via leaked databases, social media channels, blockchain tracking, or insider leaks.

Chainalysis cautions that its metrics likely underreport actual losses since many incidents go unreported. Similarly, CertiK describes its collected dataset as representative rather than comprehensive. Within CertiK’s records for the first 52 verified cases of the first half of the year, France accounted for 33 instances, while home invasions surged from a single occurrence in the first half of 2025 up to 20. This sharp upward trajectory in physical assaults was previously highlighted by Cryptopolitan.

Pressure lands on centralized platforms

The incident’s primary impact on the wider market is more likely to materialize through increased compliance and cybersecurity outlays rather than immediate price movements in cryptocurrencies. Centralized entities managing KYC repositories face heightened scrutiny to independently validate official information inquiries and restrict the volume of sensitive details a compromised workflow can leak. The European Banking Authority currently classifies cyber risk and data security as the primary operational threats facing banking institutions, followed closely by fraudulent activity.

This issue holds significant weight because consumers continue to rely heavily on centralized services. Findings from the Financial Conduct Authority (FCA) indicate that 73% of UK cryptocurrency participants acquire assets via centralized exchanges, while 25% stated that stricter oversight would encourage them to invest. Operating a platform with over 80 million users, Revolut sits squarely at the crossroads of traditional banking, digital assets, and increasingly valuable personal identity data.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It’s free.

Related stories

Comments 0 responses

Join the discussion

Comments are moderated and appear after review.