Hackers Want $3 Million in Monero for Revolut’s Stolen Bitcoin Records. What Affected Customers Should Do Now
Attackers posed as Italian law enforcement for months, convincing Revolut to hand over passports, selfies, and full transaction histories on hundreds of high-net-worth crypto holders. Here is what those customers face now and what the stolen files actually allow someone…
This post may contain links from our sponsors and affiliates, and Flywheel Publishing may receive compensation for actions taken through them.
A group that goes by the name iamnotavillain spent months emailing Revolut from an Italian government domain, posing as law enforcement and requesting files on named customers. The requests cleared Revolut’s verification, and the fintech handed over passports, the selfies customers submit for identity checks, addresses, account details and full transaction histories.
Revolut confirmed the disclosure on September 12, 2026, and notified affected customers the same day. On September 16, the group published a demand for 6,000 Monero (CRYPTO:XMR), worth roughly $3 million, with a 24-hour countdown. Revolut says it has received no direct ransom demand, which leaves the 680 people named in those files waiting on a negotiation neither side has opened.
How the Attackers Obtained the Records

The attackers first engaged in reconnaissance. They told the Financial Times they used blockchain analysis to pinpoint Revolut accounts with substantial amounts of cryptocurrency, allowing them to identify the customers they wanted to target before sending any emails. Blockchain investigator ZachXBT noted that the targets were high-net-worth individuals instead of a random mix of users.
Next came the fraudulent paperwork. The attackers created an email account using the domain of a legitimate Italian government agency, reportedly connected to the Ministry of the Interior, and submitted law enforcement information requests over several months.
Italian authorities are currently investigating how this unauthorized use of the government’s certified email system occurred. At least 680 customers across 31 countries had their files compromised.
Revolut maintains that its core systems, databases, and customer funds remain untouched, which is accurate. However, this offers little reassurance to customers. The protocols Revolut has in place for handling police requests functioned as designed, and the attackers presented themselves convincingly enough as Italian law enforcement to evade suspicion, as the number of requests did not trigger any alarms.
Why the Ransom Is Demanded in Monero

Bitcoin (CRYPTO:BTC) records all transactions on a public ledger, allowing any wallet receiving ransom payments to be tracked and blacklisted by exchanges. Companies that specialize in chain analysis monitor these transactions, enabling investigators to freeze proceeds as soon as the coins reach a regulated venue.
In contrast, Monero is designed to evade such tracking. Its protocol generates a unique temporary address for each transaction and conceals the sender, receiver, and amount, preventing a public balance from accumulating and being tracked. This makes Monero a popular choice for extortion demands.
However, the shift to Monero is not as straightforward as it might seem. Initially, a demand for 10,000 Bitcoin, approximately $780 million, circulated under the name Revolut Smilik. Iamnotavillain claims that an impersonator who received a data sample is wrongfully taking credit for the broader breach. Until Revolut or a regulatory authority confirms otherwise, both figures reflect the attackers’ claims, while only the company’s data disclosure is a factual event.
What the Stolen Files Can and Cannot Do

Certain sensitive information was protected from disclosure. Revolut has verified that the released data did not include cryptographic private keys, account passwords, security authentication codes, or full payment card details. A passport scan cannot facilitate cryptocurrency transactions, and the files do not contain keys that could unlock digital wallets.
However, the files do include a passport, a matching verification selfie, an address, an IBAN, and a complete transaction history, including cryptocurrency activity. This combination can be used to pass identity checks at other banks or exchanges, potentially opening accounts in someone else’s name and revealing the venues a person uses and their approximate holdings.
Because the 680 accounts were selected based on the size of their holdings, the risk targets specific individuals rather than the general population.
The threat has already emerged, with individuals in the cryptocurrency industry facing personal blackmail using the stolen identity documents and transaction records. Customers who ignored notifications and made no changes are now receiving these extortion messages, particularly those still relying on a password and an SMS code rather than more secure measures like a hardware key or a withdrawal whitelist.
Revolut has notified law enforcement, alerted the relevant government agency whose domain was misused, and blocked the fraudulent email channel. UK regulators are currently reviewing the situation, which arrives shortly after the company secured conditional approval to operate as a national bank.
Is Paying Ever the Answer Here?
The decision was never the customers’ to make. Revolut says it has received no direct demand, and the group published its ultimatum on a website rather than sending it to the company, which reads as pressure staged for the press rather than an opening negotiation. The group also claims to hold 147 gigabytes of data and to have reached Italian law enforcement systems, and Italian authorities have confirmed neither.
For the 680 people named in those files, the cost is already paid and cannot be refunded. The documents are out, and the only open question is who buys them next and what they do with such a precise list. A fix at Revolut alone will not close this, because every bank and exchange handling law enforcement requests runs the same process, and a group that got past one will try the next.
Contact [email protected] for any questions or corrections.







