A group claiming responsibility for an alleged Revolut customer data breach is seeking $3 million in Monero (XMR) and has given the company 24 hours to make the payment. The group warned that it would offer the stolen information to other criminal organizations if Revolut does not comply.
Calling itself “iamnotavillain,” the group published a demand for 6,000 XMR on Wednesday along with a countdown clock, the Financial Times reported.
Revolut said it has not received any direct communication from the individuals behind the claims. “Revolut has not received any direct contact or demand from the individuals or group making these claims,” a company spokesperson told CoinDesk.
The reported breach involved at least 680 customer accounts. The attackers told the FT that they used blockchain analysis to identify Revolut users whose accounts appeared to contain substantial crypto holdings.
To support its claims, the group shared a 60-second screen recording with the FT that appeared to display data obtained from affected customers. The material reportedly included passports, driver’s licenses, photographs submitted for know-your-customer verification and transaction histories.
The incident reportedly resulted from attackers impersonating government officials and submitting fraudulent requests for customer information. Those requests passed Revolut’s internal checks, prompting the company to provide customer records before determining that the requests were illegitimate, according to notifications sent to affected customers.
Revolut previously said it had blocked the address associated with the fraudulent requests and reported the incident to the relevant government authority, law enforcement and regulators. The company also said that its systems and customer funds remained unaffected.
The group told the FT that it had not entered into negotiations with Revolut as of the time the report was published.
































