A hacking group calling itself “iamnotavillain” is demanding roughly $3 million in Monero from Revolut, giving the fintech company 24 hours to pay before it starts selling stolen customer data to other criminal groups. The group posted its demand alongside a live countdown clock, asking for 6,000 XMR in exchange for not releasing the material.

The data at stake goes well beyond account numbers. According to reporting on the breach, the hackers obtained identity documents, passports, driving licenses, and the photos customers submitted for know-your-customer verification, along with transaction histories tied to those accounts. As proof, the group circulated a 60-second video showing samples of the stolen material. At least 680 Revolut customer accounts were compromised in the breach, and the attackers say they specifically targeted accounts holding significant crypto balances, using blockchain analysis to identify which customers were worth pursuing.

The intrusion itself didn't rely on a technical exploit so much as a social one. The attackers posed as government officials and submitted requests that, per the reporting, “passed Revolut's checks” — meaning the company handed over customer records before it had verified the requests were genuine. Revolut only discovered the requests were fraudulent afterward. The company has since blocked the address used to submit the fake requests and notified government agencies, law enforcement and regulators. It maintains that its systems and customer funds were unaffected, and that the exposure was limited to the KYC and identity data handed over during the fraudulent request. As of the most recent reporting on the case, no negotiations had taken place between Revolut and the hackers, and the company did not respond to a request for comment before the story published.

The attack fits a pattern of increasingly convincing social-engineering schemes aimed at crypto holders specifically — a fake GTA 6 leak site was recently found to be a multi-chain wallet drainer, and hardware-wallet makers have had to warn users directly about similarly convincing impersonation attempts, with one vendor flagging abnormal transfer patterns and urging affected users to migrate funds before their keys could be compromised. The choice of Monero for the ransom is itself a signal of intent. Unlike Bitcoin, whose transaction history is fully public and increasingly easy for chain-analysis firms to trace back to real-world identities, Monero obscures sender, receiver and amount by default, making it the preferred settlement currency for extortion groups who expect law enforcement to be watching the moment any payment moves. That choice, combined with the tight 24-hour window and the public countdown clock, points to a group trying to manufacture urgency rather than negotiate quietly — pressure tactics that have become increasingly common in data-extortion cases where the attacker never encrypted anything and has nothing to “restore,” only stolen files to threaten with.

The case also lands at an awkward moment for Revolut specifically. The fintech has spent recent years pushing hard into crypto products and expanding its user base of holders, which is precisely the population this attack targeted — customers whose KYC files show real crypto exposure and who therefore make more attractive targets for follow-on scams once their identity documents are in criminal hands. Efforts by stablecoin issuers to freeze illicit funds have gotten more aggressive over the past year, but that kind of intervention only helps once stolen funds actually move on-chain in a traceable asset — it does little against a Monero-denominated ransom demand that, by design, never touches a transparent ledger. For the 680 affected customers, the practical risk now shifts from account security to a longer tail of identity-theft exposure, regardless of whether Revolut ultimately pays.