Key Points
- Cybercriminals identifying as “iamnotavillain” issued an ultimatum to Revolut for 6,000 Monero (approximately $3 million) with a 24-hour deadline
- A minimum of 680 customer accounts compromised following fraudulent information requests disguised as official government inquiries
- Compromised information encompasses passport copies, driver’s licenses, identification photographs, and complete account transaction records
- Attackers leveraged blockchain tracking technology to identify victims holding substantial cryptocurrency assets
- According to Revolut, core infrastructure and customer financial assets remain secure
Cybercriminals are extorting $3 million from Revolut following a sophisticated social engineering attack that resulted in unauthorized access to sensitive customer information.
The threat actors, operating under the moniker “iamnotavillain,” published their ransom demand on Wednesday, accompanied by a digital countdown timer. They issued an ultimatum requiring payment within 24 hours, threatening to distribute the compromised data to additional criminal networks if their demands remain unmet.
The extortion request specifically calls for 6,000 Monero tokens, a privacy-centric digital currency that obscures transactional metadata such as sender identity, recipient information, and transfer amounts.
Details of the Security Incident
The perpetrators avoided direct infiltration of Revolut’s technical infrastructure. Rather, they executed a social engineering scheme by impersonating government authorities, submitting data requests through what appeared to be authentic governmental email infrastructure.
These fraudulent requests successfully bypassed Revolut’s verification protocols, resulting in the disclosure of customer information before the deception was identified. Upon detection, Revolut immediately blocked the compromised email channel and notified appropriate law enforcement agencies, financial regulators, and the impersonated government entity.
The incident impacted a minimum of 680 user accounts, though Revolut characterized this as representing a “very limited” percentage of its total user population.
The scope of compromised data is substantial. Exposed information includes complete legal names, birth dates, residential addresses, email contacts, telephone numbers, passport documentation, driver’s license records, and photographic identification submitted during account verification procedures.
Financial account details were similarly compromised, encompassing bank account identifiers, account establishment dates, comprehensive transaction logs, and Bitcoin wallet reference codes.
Revolut has verified that cryptographic private keys, account passwords, authentication codes, and complete payment card credentials were not included in the breach.
Targeted Attack on Crypto Holders
The cybercriminals revealed to the Financial Times that they employed blockchain forensic tools to pinpoint Revolut users possessing substantial cryptocurrency portfolios. On-chain security researcher ZachXBT had earlier indicated the incident specifically targeted affluent users.
Transparent blockchain networks enable visibility into wallet holdings, historical transactions, and fund movements across addresses. When this publicly available blockchain data is correlated with personal identification information maintained by financial platforms, it can reveal an individual’s complete cryptocurrency activities.
The leaked Revolut documentation reportedly bridges both elements, potentially elevating the risk profile for affected customers regarding sophisticated phishing attempts and social engineering attacks.
Monero was selected as the ransom currency due to its enhanced privacy mechanisms that complicate forensic tracking compared to more transparent cryptocurrencies like Bitcoin or Ethereum.
The Financial Times indicated that no dialogue between Revolut and the threat actors had occurred as of their report’s publication. Revolut has not publicly stated whether they intend to engage with the extortion demand.





