Hackers Want $3 Million in Monero for Revolut’s Stolen Bitcoin Records. What Affected Customers Should Do Now

Attackers posed as Italian law enforcement for months, convincing Revolut to hand over passports, selfies, and full transaction histories on hundreds of high-net-worth crypto holders. Here is what those customers face now and what the stolen files actually allow someone…

Published September 18, 2026, 9:50am ET · 4 min read

This post may contain links from our sponsors and affiliates, and Flywheel Publishing may receive compensation for actions taken through them.

A person in a dark hoodie is seen from behind, sitting at a wooden desk in a dimly lit room. A large computer monitor in front displays green text on a dark background, prominently featuring 'YOU HAVE BEEN HACKED!'. A white keyboard is on the desk, along with a white mug. The person's right hand is interacting with a tablet that also shows green glowing text. A notebook and pen are also visible on the desk.
A hooded figure works in a dimly lit room, illuminated by screens displaying code and the alarming message 'YOU HAVE BEEN HACKED!', underscoring the severe risks of cyberattacks on financial data. © PeopleImages.com - Yuri A / Shutterstock.com

A group that goes by the name iamnotavillain spent months emailing Revolut from an Italian government domain, posing as law enforcement and requesting files on named customers. The requests cleared Revolut’s verification, and the fintech handed over passports, the selfies customers submit for identity checks, addresses, account details and full transaction histories.

Revolut confirmed the disclosure on September 12, 2026, and notified affected customers the same day. On September 16, the group published a demand for 6,000 Monero (CRYPTO:XMR), worth roughly $3 million, with a 24-hour countdown. Revolut says it has received no direct ransom demand, which leaves the 680 people named in those files waiting on a negotiation neither side has opened.

How the Attackers Obtained the Records

Hacker in hoodie using laptop computer with digital database folded on blurry blue background with reflections. Digital transformation, hacking, data theft and media concept

Who is Danny / Shutterstock.com

The attackers first engaged in reconnaissance. They told the Financial Times they used blockchain analysis to pinpoint Revolut accounts with substantial amounts of cryptocurrency, allowing them to identify the customers they wanted to target before sending any emails. Blockchain investigator ZachXBT noted that the targets were high-net-worth individuals instead of a random mix of users.

Next came the fraudulent paperwork. The attackers created an email account using the domain of a legitimate Italian government agency, reportedly connected to the Ministry of the Interior, and submitted law enforcement information requests over several months.

Italian authorities are currently investigating how this unauthorized use of the government’s certified email system occurred. At least 680 customers across 31 countries had their files compromised.

Revolut maintains that its core systems, databases, and customer funds remain untouched, which is accurate. However, this offers little reassurance to customers. The protocols Revolut has in place for handling police requests functioned as designed, and the attackers presented themselves convincingly enough as Italian law enforcement to evade suspicion, as the number of requests did not trigger any alarms.

Why the Ransom Is Demanded in Monero

Cryptocurrency concept. Shining Monero cryptocurrency coin in front of five gold bars and by an old vintage pocket watch, isolated in white background. selective focus.

LEE WA DA / Shutterstock.com

Bitcoin (CRYPTO:BTC) records all transactions on a public ledger, allowing any wallet receiving ransom payments to be tracked and blacklisted by exchanges. Companies that specialize in chain analysis monitor these transactions, enabling investigators to freeze proceeds as soon as the coins reach a regulated venue.

In contrast, Monero is designed to evade such tracking. Its protocol generates a unique temporary address for each transaction and conceals the sender, receiver, and amount, preventing a public balance from accumulating and being tracked. This makes Monero a popular choice for extortion demands.

However, the shift to Monero is not as straightforward as it might seem. Initially, a demand for 10,000 Bitcoin, approximately $780 million, circulated under the name Revolut Smilik. Iamnotavillain claims that an impersonator who received a data sample is wrongfully taking credit for the broader breach. Until Revolut or a regulatory authority confirms otherwise, both figures reflect the attackers’ claims, while only the company’s data disclosure is a factual event.

What the Stolen Files Can and Cannot Do

Business man using smartphone and computer that show warning sign after got attack phishing email by malware from hacker that commit cyber crime or software crash to cause an error.

BritCats Studio / Shutterstock.com

Certain sensitive information was protected from disclosure. Revolut has verified that the released data did not include cryptographic private keys, account passwords, security authentication codes, or full payment card details. A passport scan cannot facilitate cryptocurrency transactions, and the files do not contain keys that could unlock digital wallets.

However, the files do include a passport, a matching verification selfie, an address, an IBAN, and a complete transaction history, including cryptocurrency activity. This combination can be used to pass identity checks at other banks or exchanges, potentially opening accounts in someone else’s name and revealing the venues a person uses and their approximate holdings.

Because the 680 accounts were selected based on the size of their holdings, the risk targets specific individuals rather than the general population.

The threat has already emerged, with individuals in the cryptocurrency industry facing personal blackmail using the stolen identity documents and transaction records. Customers who ignored notifications and made no changes are now receiving these extortion messages, particularly those still relying on a password and an SMS code rather than more secure measures like a hardware key or a withdrawal whitelist.

Revolut has notified law enforcement, alerted the relevant government agency whose domain was misused, and blocked the fraudulent email channel. UK regulators are currently reviewing the situation, which arrives shortly after the company secured conditional approval to operate as a national bank.

Is Paying Ever the Answer Here?

The decision was never the customers’ to make. Revolut says it has received no direct demand, and the group published its ultimatum on a website rather than sending it to the company, which reads as pressure staged for the press rather than an opening negotiation. The group also claims to hold 147 gigabytes of data and to have reached Italian law enforcement systems, and Italian authorities have confirmed neither.

For the 680 people named in those files, the cost is already paid and cannot be refunded. The documents are out, and the only open question is who buys them next and what they do with such a precise list. A fix at Revolut alone will not close this, because every bank and exchange handling law enforcement requests runs the same process, and a group that got past one will try the next.

Contact [email protected] for any questions or corrections.

Sam Daodu

Sam Daodu is a crypto analyst who's spent nearly a decade making blockchain understandable—no easy task when most whitepapers read like fever dreams. He writes for 24/7 Wall St., covering Bitcoin, altcoins, and crypto market analysis for investors. Before crypto, he was a tech writer (back when explaining "the cloud" was peak innovation). Since 2018, he's written for CoinTelegraph, Yahoo Finance, The Block, Cryptonews, Zypto, Rain, and more—basically anywhere people want crypto news without the headache. Sam runs MacLabs Marketing, a content agency for crypto brands tired of sounding like AI wrote their website. He also publishes free crypto education on his site for Web3 enthusiasts who think "gas fees" is a typo. When he's not writing or staring at charts, Sam's either: - Watching anime (currently convinced One Piece has better tokenomics than most altcoins) - At the gym sculpting himself into a Greek god - Listening to the music your mum warned you only bad boys listen to Connect: LinkedIn | Email | MacLabs Marketing

All articles →