Meet the Top 101 in Crypto
Bitcoin (BTC)
3 min read

Revolut Hacker Launches Extortion Site Demanding $3M After 680 Customer Data Breach

Published 18 September 2026
Dr. Guneet Kaur
Authors

Key Takeaways

  • A group claiming responsibility for the Revolut breach has demanded 6,000 Monero, worth roughly $3 million, and threatened to sell stolen customer records.
  • Around 680 customers were affected after fraudulent data requests were sent using an email account on a legitimate Italian government domain.
  • Revolut says its own systems and customer funds were not compromised and that it has received no direct ransom demand from the alleged attackers.

Hackers claiming responsibility for Revolut’s recent customer data breach have launched a public extortion site demanding $3 million in Monero, escalating an incident that exposed sensitive information belonging to hundreds of customers.

The group, calling itself “iamnotavillain,” posted a demand for 6,000 XMR alongside a 24-hour countdown, threatening to sell the stolen records to other criminal groups if Revolut refused to pay.

Revolut, however, told Reuters that it had received no direct communication or ransom demand from the people claiming responsibility and had not entered negotiations.

Try Our Recommended Crypto Exchanges
Sponsored
Disclosure
Opened in 2011
Promotions
Get $10 in Bitcoin when you register through a referral link from an existing member.
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +81
Promotions
Receive up to $100,000 worth of exclusive gifts for newcomers upon registration.
Coins
Bitcoin Ethereum Tether USD Coin Solana +76
Opened in 2017
Promotions
Unlock 1,500+ cryptocurrencies and seamless instant swaps in the all-in-one crypto super app ChangeNOW
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +217
 

680 Customers Exposed Without Revolut Being Hacked

The breach did not begin with attackers breaking into Revolut’s core systems.

Instead, an unauthorized party used an email account on a legitimate government agency domain to submit fraudulent requests for customer information. Revolut complied with some of those requests before discovering the deception and blocking the address.

Around 680 customers across several European countries were affected, according to people familiar with the incident. Potentially exposed records included names, home addresses, phone numbers, identity documents, verification selfies, IBANs and transaction histories —including information about Bitcoin activity.

The attackers told the Financial Times they had compromised an Italian government email system and used blockchain analysis to identify Revolut customers believed to hold significant amounts of cryptocurrency. Revolut has not independently confirmed those claims.

Former Mt. Gox CEO Mark Karpelès was among those affected and has publicly raised concerns about the physical-security implications of having home addresses and crypto-related information exposed.

Try Our Recommended Crypto Exchanges
Sponsored
Disclosure
Opened in 2011
Promotions
Get $10 in Bitcoin when you register through a referral link from an existing member.
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +81
Promotions
Receive up to $100,000 worth of exclusive gifts for newcomers upon registration.
Coins
Bitcoin Ethereum Tether USD Coin Solana +76
Opened in 2017
Promotions
Unlock 1,500+ cryptocurrencies and seamless instant swaps in the all-in-one crypto super app ChangeNOW
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +217

Italian Prosecutors Open Investigation

The incident has now drawn law-enforcement attention in Italy.

Prosecutors in Reggio Calabria have opened an investigation after the fraudulent requests were linked to an institutional email account belonging to the local prefecture. Authorities are examining whether the government system itself was breached or whether the account was cloned. Italy’s National Anti-Mafia and Anti-Terrorism Directorate is also involved.

Revolut maintains that customer funds and its internal systems remain unaffected and says it has notified law enforcement, regulators and affected customers.

The breach nevertheless highlights a different security problem: attackers did not need to penetrate an 80-million-customer fintech’s infrastructure. They allegedly exploited the trust attached to a government email account instead.

 

Disclaimer: The information provided in this article is for informational purposes only. It is not intended to be, nor should it be construed as, financial advice. We do not make any warranties regarding the completeness, reliability, or accuracy of this information. All investments involve risk, and past performance does not guarantee future results. We recommend consulting a financial advisor before making any investment decisions.
Dr. Guneet Kaur

Dr. Guneet Kaur is a senior editor at CCN.com and a Science Fellow at Exponential Science. She is a fintech and blockchain expert with extensive experience in digital finance education, blockchain ecosystems, and cryptocurrency markets. She has worked with global media such as Cointelegraph, as well as education and blockchain platforms, to design and lead strategic content and learning initiatives. As an educator and assessor for top-tier executive programs, she bridges real-world fintech trends with academic insight.

Dr. Kaur is also a published researcher and peer reviewer across fintech and data science journals, including Financial Innovation Journal and International Journal of Big Data Intelligence and Applications. Her work spans data-driven analysis, Web3 innovation, and technical content development. With a strong foundation in both industry and academia, she translates complex financial technologies into practical applications, empowering learners, professionals, and institutions across the rapidly evolving digital finance landscape.

Related

Survey Icon
Help us improve
1 of 4
Is this your first time here?
What brought you here today?
What are you most interested in?
Would you be interested in:
Thank you icon
Thank you for your feedback!
DMCA.com Protection Status