Short answer: Revolut has confirmed that an attacker used a genuine government email account to send fake legal data requests and obtained records on about 680 customers, including passport scans, verification selfies and transaction histories with bitcoin activity. The group behind it, calling itself "IAmNotAVillain", says it picked the victims through blockchain analysis because they held significant crypto, and on September 16, 2026 demanded 6,000 XMR (about $3 million) within 24 hours — a deadline running out on September 17, 2026. Revolut says its systems and customer funds were not affected.
What happened
Revolut began notifying affected customers on Friday, September 11, 2026, describing the incident as a sophisticated external impersonation scam. Banks and fintechs routinely receive information requests from police and courts, and have to answer them. In this case the requests came from a legitimate state mailbox. According to reports citing the attackers, the channel was PEC, Italy's certified email system, which gives messages legal standing. The emails passed standard authentication checks (SPF, DKIM and DMARC), so compliance staff treated them like routine legal demands and handed over customer files. The hackers told the Financial Times the exchange ran over several months.
After discovering the fraud, Revolut blocked the address and informed the authorities. The UK Information Commissioner's Office said it was assessing the report, and the Financial Conduct Authority is engaging with the company. Revolut's EU business operates through a Lithuanian bank supervised by the Bank of Lithuania and the European Central Bank.
On Wednesday, September 16, the group published a ransom page with a countdown, demanding 6,000 XMR, worth roughly $3 million, and threatening to sell the records to other criminal groups if unpaid. Revolut told reporters it had not received a direct demand. At the time of writing there was no public confirmation of what followed the deadline.
What was exposed
| Item | Detail |
|---|---|
| Customers affected | About 680, mostly in Switzerland and France, plus 31 other mainly European countries |
| Identity data | Names, dates of birth, occupations, home addresses, emails, phone numbers |
| KYC documents | Passport or driving licence copies, verification selfies |
| Account data | IBANs, account statements, withdrawal records, transaction histories including bitcoin transactions |
| Not compromised (per Revolut) | Core systems and customer funds; reports say no passwords, PINs or private keys were taken |
| Method | Fraudulent information requests from a real government mailbox |
| Ransom demand | 6,000 XMR (about $3 million), 24-hour countdown from September 16, 2026 |
Why does this breach matter to crypto holders?
Most data leaks are indiscriminate: a database is copied and sold in bulk. This one was selective. The attackers say they started from the blockchain side, looked for wallets with large balances, linked them to Revolut accounts and only then requested the data. The result is a file that ties real names, home addresses and identity photos to people known to hold significant crypto. That combination is more dangerous than a stolen password, because a password can be changed and a home address cannot.
There are three realistic ways such data gets used:
- Targeted phishing. A caller or email that knows your full name, date of birth, IBAN and recent transactions is far more convincing when it claims to be your bank's fraud team or an exchange's support desk.
- Account takeover attempts. Identity documents and selfies can be reused to pass verification at other services or to talk a mobile carrier into a SIM swap.
- Physical threats. So-called wrench attacks — robbery or extortion of crypto holders in person — depend precisely on knowing who holds crypto and where they live.
Why ask for Monero?
Bitcoin payments are visible on a public ledger, so a large ransom paid in BTC can be followed across exchanges by investigators. Monero hides amounts and counterparties by design, which makes tracing a payment much harder. That is the practical reason extortion groups prefer it — it says nothing about ordinary users who hold XMR for privacy.
The wider lesson: KYC data is a liability that lasts
Identity checks exist for sound regulatory reasons, but every copy of a passport scan held by a company is a copy that can leak. Here the weak point was not a hacked server but a trusted legal process, which shows how hard it is to secure such data completely. For anyone who holds crypto, the sensible assumption is that personal data given to any service may one day become public.
What to do: a practical checklist
If you are a Revolut customer:
- Check the in-app notifications and the email address linked to your account for a message from Revolut about this incident. Do not rely on links in unsolicited emails or text messages.
- Treat any call claiming to be from Revolut, the police or a regulator as suspect, even if the caller knows your details. Hang up and contact the company through the app.
- Never move funds to a "safe account" or install remote-access software at someone's request. No legitimate bank asks for either.
- Ask your mobile carrier to add a port-out PIN or SIM-swap protection, and switch two-factor authentication from SMS to an authenticator app or hardware key where possible.
For all crypto holders:
- Keep significant holdings in self-custody with a hardware wallet and an offline seed backup — see our self-custody wallet security guide. Leaked data cannot sign a transaction.
- Separate identity from addresses. Avoid publicly linking your name or social accounts to wallet addresses, and use fresh receiving addresses where your wallet supports it.
- Watch for poisoned addresses and signature requests. Targeted victims often receive lookalike transactions or fake approval prompts; address poisoning and signature phishing explains the patterns.
- Share documents only when required. For small swaps, services that do not ask for identity documents mean fewer copies of your passport in circulation, where that is legal in your country. You can compare such services on the exchangers list and check each one's verification terms before sending.
- Be discreet offline. Do not discuss holdings publicly, and consider what your address and routines reveal if your data is already out.
FAQ
What happened in the Revolut data breach?
An attacker used a legitimate government email account to send fraudulent law-enforcement style data requests to Revolut, which handed over records on about 680 customers. Revolut began notifying affected customers on September 11, 2026 and says its systems and customer funds were not affected.
What data was leaked?
Names, dates of birth, addresses, emails and phone numbers, copies of passports or driving licences, verification selfies, IBANs, account statements, withdrawal records and transaction histories that in some cases included bitcoin transactions.
How much ransom did the hackers demand?
On September 16, 2026 the group calling itself IAmNotAVillain demanded 6,000 XMR, worth about $3 million, within 24 hours and threatened to sell the data to other criminals. Revolut said it had not received a direct demand.
Were crypto funds stolen from Revolut accounts?
No theft of funds has been reported. Revolut says customer funds were unaffected, and reports indicate that no passwords, PINs or private keys were exposed. The main risk is follow-up scams and targeting using the leaked personal data.
What should I do if my data may have leaked?
Distrust unexpected calls and messages even if they know your details, contact the company only through its official app, protect your phone number against SIM swaps, use app-based or hardware two-factor authentication and keep significant crypto in a self-custody hardware wallet.
Sources
- CoinDesk: Revolut hackers demand $3 million in Monero, threaten to sell customer data
- The Irish Times: Hackers say they breached Italian state email to target Revolut crypto whales
- The Crypto Times: Revolut Data Breach Hits 680 Customers, UK Opens Probe
- The Crypto Times: Revolut Hackers Cut Ransom to $3M, Set 24-Hour Deadline to Sell 680 Customer Files
- Cryptopolitan: Revolut hackers demand $3 million as breach exposes crypto holders' data