A group of hackers operating under the alias Iamnotavillain has demanded a $3 million ransom in Monero (XMR) from Revolut, threatening to leak customer data if the payment is not made within 24 hours. The breach allegedly impacted at least 680 customers, with hackers obtaining IDs, passports, selfies, addresses, and transaction data through social engineering by impersonating Italian law enforcement. Revolut stated it did not receive a ransom request directly and that core systems and customer funds were not at risk. The hackers claim blockchain analysis allowed them to identify customers with large cryptocurrency balances. The demand for Monero highlights the privacy-focused cryptocurrency’s appeal to criminals, though Norwegian police recently reported developing limited capabilities to trace certain Monero transactions as part of an international investigation.
Hackers using the alias Iamnotavillain have demanded a $3 million ransom from Revolut, payable in Monero (XMR), as reported. The attackers threatened to sell stolen customer information to other criminals if the 24-hour deadline is not met.
The breach allegedly affected at least 680 Revolut customers. The hackers gained access by impersonating Italian law enforcement and sending requests through an Italian government email account.
Stolen data includes IDs, passports, self-taken identity verification photos, addresses, and transaction information. The hackers claim blockchain analysis allowed them to identify customers with substantial cryptocurrency balances.
Revolut stated it did not receive any ransom request directly, according to Reuters. The company said its core systems and customer funds were not at risk and has blocked the email address used by the attackers.
The demand for 6,000 XMR highlights Monero‘s privacy features, which make transactions more difficult to trace than Bitcoin. Norwegian police reported in 2025 that they developed the ability to trace certain Monero transactions in specific cases, as stated.
That investigation led to 28 arrests across seven countries. Authorities have not disclosed that Monero‘s underlying cryptography has been compromised, and “certain transactions” does not imply all Monero activity can be traced.
Monero uses ring signatures, stealth addresses, and anonymous transaction amounts to prevent linking transactions to specific users. Investigators may also rely on data beyond the blockchain, including seized devices, account records, operational errors, and traditional detective work.
Revolut has stated it was not directly contacted by the alleged hackers. The situation remains under investigation.
