πŸš€ Premium Banner Placement β€” Reach 100K+ daily crypto readersAdvertise with us β†’
LIVE
BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”
β€”β–²0.0%
News

Revolut Hackers Demand 6,000 Monero for 680 Customer Files

17 Sept 2026by CryptoJazz Admin1 min read7 views
Revolut Hackers Demand 6,000 Monero for 680 Customer Files

The group holding customer files taken from Revolut has named a price. It wants 6,000 monero, about $3 million at Wednesday's prices, and it posted a countdown clock giving the company 24 hours to pay. Unpaid, the files go to other criminal groups, the demand says. Roughly 680 customers are covered by it. Revolut says nobody has contacted it.

The price came down before any of this went public

Four accounts agree on the demand as it stands: 6,000 XMR, a 24-hour clock, and a group calling itself iamnotavillain. What came before it depends on who is reading. The Crypto Times and Bitcoin.com both report an earlier demand of 10,000 bitcoin, which the first of them values at about $780 million. CoinDesk and CoinGape describe the monero figure and mention no earlier one. Neither pair says the other is wrong, and we could not establish when the number moved. The switch of currency is the part worth reading twice. Monero's ledger conceals sender, receiver and amount, so a payment made in it leaves nothing like the trail a bitcoin payment leaves.

What is in the 680 files

They are complete customer records. Passports, driving licences, the selfies taken for identity checks, IBANs, account statements, names, addresses, phone numbers and full bitcoin transaction histories all appear on the lists published by The Crypto Times, Bitcoin.com and CoinGape. What is absent gets described two ways. The Crypto Times quotes Revolut saying no private keys, card PINs or account balances were listed. CoinGape quotes the company saying funds, passwords, private keys and full card details were not taken. Balances sit in the first list and not the second, passwords in the second and not the first. The two do not reconcile. CoinDesk reports that the group showed its access by sharing a 60-second screen recording of sample data with the Financial Times, which no other account mentions.

The request that took them came from a working mailbox

Nothing was broken into. The Crypto Times, Bitcoin.com and CoinGape all describe information requests sent through Italy's certified email system, a state-backed service whose messages carry legal weight, from an address that passed authentication and reached compliance staff looking like a lawful demand. Revolut answered it. This desk reported the disclosure on 13 September, when a request from a real government domain was called a sophisticated impersonation scam by the company and no figure for affected customers was given. The figure now in circulation comes from the attackers, not from Revolut. Trusted senders have been the way in all month, and phishing mail reached Trezor's customers from Trezor's own domain earlier in September.

Twenty-four hours, and nobody talking

CoinDesk reported on Wednesday evening that there had been no negotiations, and Bitcoin.com says Revolut received no direct demand at all. The company declined to comment to CoinDesk before publication. Its public position is still the statement it gave at the weekend.

Revolut said it had "identified the impersonation scam, blocked the address, and notified the relevant agency, law enforcement, and regulators," in wording carried by Bitcoin.com.

Who the 680 are is partly known. CoinDesk and CoinGape both say the group picked them with on-chain analysis, hunting for the accounts with real crypto activity behind them. The Crypto Times places them across Europe with concentrations in Switzerland and France, while Bitcoin.com counts 31 countries with the same two concentrations, a tally that stands on one account. The Crypto Times alone reports the UK's Information Commissioner's Office and the Financial Conduct Authority looking into it. A clock set for 24 hours on Wednesday has run down by now. None of the four accounts says what the group has said it will do the moment it does.

Read also: Blockstream Refuses a 10% Bounty for Liquid's Missing 598 BTC

← All news