cryptocurrency widget, price, heatmap
arrow
Burger icon
cryptocurrency widget, price, heatmap
News/Revolut Data Breach Leads to 6,000 XMR Extortion Demand

Revolut Data Breach Leads to 6,000 XMR Extortion Demand

Van Thanh Le

Van Thanh Le

PublishedSep 17 2026

UpdatedSep 17 2026

7 hours ago3 minutes read
Revolut robot discovers fraudulent government data request during breach investigation

Attackers say crypto-heavy customers were deliberately targeted through fraudulent government requests

TL;DR

  • Attackers calling themselves Iamnotavillain demanded 6,000 XMR, valued at roughly $3 million, after claiming possession of about 680 Revolut customer files.
  • Revolut said its core systems and customer funds were not compromised, calling the incident a “sophisticated external impersonation scam.”
  • The attackers said they used a legitimate Italian government email channel and onchain analysis to target customers with substantial cryptocurrency activity.

Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity. 

Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!


Attackers claiming responsibility for a Revolut customer-data breach demanded 6,000 Monero, or XMR, valued at roughly $3 million, after saying they obtained files on about 680 customers through fraudulent government information requests rather than a breach of Revolut’s core systems. Revolut said customer funds were not compromised and described the incident as a “sophisticated external impersonation scam,” while the attackers said they deliberately sought information on customers with significant cryptocurrency activity.

Revolut said an unauthorized party used an email account on the domain of a legitimate government agency to submit fraudulent customer-information requests. Once Revolut became aware of the activity, the company said it blocked the email address. Revolut has characterized the number of affected customers as “limited” rather than confirming the approximately 680-file figure cited by a source referenced by Reuters.

The attackers, who call themselves Iamnotavillain, told Financial Times reporters Tom Wilson, Laith Al-Khalaf and Amy Kazmin through “a series of messages” that they had posed as Italian law-enforcement officials for months. They said Revolut responded to requests for specific customer records, allowing the group to collect passports, verification selfies, transaction histories and other sensitive information without penetrating Revolut’s underlying systems.

Fraudulent requests used a legitimate government email channel

The operation allegedly relied on Italy’s Posta Elettronica Certificata, or PEC, certified-email system, which is used for government and legal communications. Messages sent through the compromised channel carried legitimate domain-authentication credentials. That could establish that an email originated from the government domain, but not that the person controlling the account was an authorized official. The attackers said they exploited the process for handling lawful government requests rather than breaking through Revolut’s technical security controls.

Revolut confirmed that fraudulent requests came from an email account associated with a legitimate government-agency domain. The attackers separately claimed they had hacked an Italian government email system, but Revolut did not independently confirm that claim. The distinction leaves the compromised government communications channel established by Revolut, while the attackers’ account of how they obtained control of it remains their own claim.

The attackers said the customer selection was deliberate. They claimed to have conducted blockchain-focused analysis to identify Revolut customers with substantial cryptocurrency holdings or activity before requesting records on those individuals by name. Financial Times reporting placed the affected group across 31 countries, with many of the customers in Switzerland and France.

Onchain analyst ZachXBT also said the pattern appeared targeted. “While the incident is likely limited in size it seems to have been targeted at high net worth users,” ZachXBT said.

The exposed information was described as including names, dates of birth, home addresses, phone numbers, account IDs, passport and driver’s-license copies, other identity documents, KYC records, verification selfies, bank and account statements, IBANs, fiat transfers, crypto deposits and withdrawals, and broader transaction histories. Notifications reviewed by TechCrunch and The Block indicated that some records included full transaction histories containing Bitcoin transactions.

Former Mt. Gox executive Mark Karpelès said he was affected and shared a Revolut notification indicating that information about Bitcoin transactions had been disclosed. “Revolut customers were targeted in a fraudulent emergency data request sent via an email at a ‘government agency,’” Karpelès said.

Iamnotavillain sets a public deadline

Revolut publicly disclosed the impersonation incident on Sept. 12, 2026, saying it had identified and blocked the fraudulent channel and had notified the government agency concerned, law enforcement and regulators. The company maintained that the incident involved unauthorized disclosure of customer information rather than a compromise capable of directly accessing customer funds.

Iamnotavillain escalated the incident into an extortion attempt on Sept. 16, posting a public ultimatum on a website using the group’s name. The group set a 24-hour deadline and threatened to sell the customer records to other criminal groups if payment was not made. Reuters said Revolut had received no ransom demand or direct contact from the attackers at the time of its reporting, separating the public ultimatum from any direct negotiation with the company.

An earlier 10,000 BTC demand circulated through Telegram, but Iamnotavillain later said that demand came from either an impersonator or a former associate. The group’s later public demand was denominated in Monero, whose transaction details are designed to be obscured compared with Bitcoin’s publicly visible ledger.

Exposed KYC data raises physical-security concerns

The disclosure creates an additional risk for crypto holders because identity records can connect publicly visible blockchain activity with a real person and physical address. Chainalysis said many violent crypto attacks are premeditated and that victims can be identified through leaked information, social media, blockchain analysis or insider data.

Chainalysis estimated that more than $30 million had been stolen in violent “wrench attacks” by mid-2026 and said its figures likely undercount actual losses because many incidents go unreported. A separate graphic referenced $124.1 million in exposure and 52 verified crypto wrench-attack incidents during 2026, though the accompanying material did not equate the exposure figure with confirmed theft.

CertiK characterized its own physical-attack dataset as indicative rather than exhaustive. Its H1 figures showed France accounting for 33 of the 52 verified cases, while home invasions increased from one case in H1 2025 to 20 cases in H1 2026.

Metric Figure Source attribution
UK crypto users obtaining assets through centralized exchanges 73% FCA research
UK crypto users saying tighter regulation would increase their likelihood of investing 25% FCA research
Revolut customer base More than 80 million customers Revolut figure cited in the supplied reporting

The European Banking Authority’s June 2026 risk assessment ranked cyber risk and data security as the leading operational-risk driver for banks, followed by fraud. Revolut has also received conditional approval to form a U.S. national bank, placing the breach alongside broader questions about how centralized financial institutions authenticate official requests for highly sensitive customer information.

The incident also comes as crypto activity remains heavily concentrated on centralized services, where platforms can retain extensive KYC data even when customer assets later move elsewhere. The breach showed how a compromised trusted communications process can expose identity documents and transaction histories without requiring attackers to penetrate the financial institution’s core infrastructure.

This article has been refined and enhanced by ChatGPT.

cryptocurrency widget, price, heatmap
v 5.14.18
© 2017 - 2026 COIN360.com. All Rights Reserved.