Hackers claiming responsibility for a Revolut data breach have demanded ₹28.73 crore in Monero, threatening to sell customer records if unpaid. The alleged breach affected at least 680 accounts and exposed identity documents, KYC images and transaction histories.

Hackers Demand ₹28.73 Crore Ransom From Revolut After Data Breach

The420 Correspondent
4 Min Read

Hackers claiming responsibility for a data breach affecting Revolut customers have demanded a $3 million (approx. ₹28.78 crore) ransom, threatening to sell confidential records to other criminal groups unless the online bank pays within 24 hours.

The group, calling itself “iamnotavillain”, posted the ultimatum on its website alongside a digital countdown clock. It demanded payment of 6,000 XMR, or about $3 million, in Monero, a cryptocurrency whose transactions are difficult to trace.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

The group said there had been no negotiations with Revolut. Revolut, however, said on Wednesday evening that it had received no direct contact or demand from the individuals or group making the claims.

Customer Identity and Transaction Records Allegedly Exposed

The hackers displayed redacted screenshots of information they claimed had been obtained from Revolut and later shared a 60-second screen-recording showing an unidentified user navigating through a collection of purported customer documents.

The material shown appeared to include driving licences, passports, identity photographs submitted as part of know-your-customer verification and customer transaction histories.

The breach is understood to have affected at least 680 customer accounts.

Several affected customers have raised concerns about their personal information being compromised. Revolut has previously said it was providing immediate support to affected customers and working closely with relevant law enforcement and regulatory authorities.

The public ransom demand is unusual because extortion groups typically approach organisations privately before publishing details of an attack or stolen information if payment negotiations fail.

Italian Government Email System Allegedly Used

The attackers allegedly obtained customer information after compromising an Italian government email system and using it to impersonate law enforcement authorities.

The compromised system was allegedly used over several months to submit requests seeking information about specific Revolut customer accounts. By posing as legitimate authorities, the attackers were allegedly able to obtain sensitive records connected to targeted customers.

The group said it selected targets using blockchain analysis to identify Revolut accounts believed to hold significant cryptocurrency assets.

The incident has therefore raised concerns not only about the exposure of customer identity records, but also about how compromised official communication systems can potentially be exploited to obtain confidential financial information.

The hackers’ demand warned that the data would be sold if the ransom was not paid within the specified period. There is no information establishing that Revolut has agreed to make any payment.

Ransom Demand Adds New Pressure After Breach

The latest ransom demand adds another layer to the breach as Revolut and authorities deal with the possible exposure of sensitive financial and identification records.

The group has publicly identified itself as being responsible for the incident and has threatened to sell the information to other criminal groups. Revolut has said it has not received any direct demand from those making the claims.

The bank, launched in 2015, operates in more than 30 countries and serves about 80 million customers. It has grown into Europe’s largest financial technology company and was recently valued at $115 billion (₹11.01 lakh crore) in a secondary share sale.

The immediate focus remains on the security of the affected customer accounts, the authenticity and extent of the information claimed by the hackers, and efforts by law enforcement and regulatory authorities to investigate the breach.

About the author — Suvedita Nath is a science student with a growing interest in cybercrime and digital safety. She writes on online activity, cyber threats, and technology-driven risks. Her work focuses on clarity, accuracy, and public awareness.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected