Revolut hit by $3m extortion demand after hackers access 680 customer records
Revolut is reportedly facing a $3 million ransom demand after hackers obtained sensitive information belonging to hundreds of its customers and threatened to sell the data to other criminal groups.

The group behind the extortion attempt, calling itself “iamnotavillain,” reportedly demanded 6,000 Monero, a privacy-focused cryptocurrency worth approximately $3 million, and gave the fintech company 24 hours to pay. The hackers threatened to sell the stolen information if the demand was not met.
Attack Exploited Fake Government Requests
The ransom demand follows Revolut’s confirmation last week that an unauthorized party had obtained customer information through fraudulent requests that appeared to come from a legitimate government agency email domain.
According to reporting from Reuters and other outlets, the breach affected approximately 680 customers. The attackers allegedly used a compromised Italian government email system to impersonate law enforcement officials and request information about specific Revolut customers over a period of several months.
The compromised information could include names, dates of birth, home and email addresses, phone numbers, passports, driver's licenses and verification selfies. Some affected customers may also have had bank statements and transaction histories exposed.
The attackers reportedly targeted customers believed to hold significant cryptocurrency assets. They told the Financial Times that blockchain analysis was used to identify potential targets, although those claims have not been independently verified.
Revolut Says Core Systems Were Not Compromised
Revolut has emphasized that its core systems and customer funds were not compromised. The company said it identified the impersonation scheme, blocked the fraudulent address and notified the relevant government agency, law enforcement bodies, regulators and affected customers.
The company has also disputed the characterization of the latest development as a direct ransom negotiation. A Revolut spokesperson told Reuters that the company had not received any direct contact or ransom demand from the individuals claiming responsibility for the breach.
Italian authorities have opened an investigation into the incident, with prosecutors in Reggio Calabria examining the suspected misuse of a government email account. Italy's National Anti-Mafia and Counter-Terrorism Directorate is also involved because the suspected attack involved a government entity.
The Bigger Cybersecurity Risk
The incident highlights the risks financial institutions face from social engineering and impersonation attacks, even when their core infrastructure remains secure. Rather than directly breaking into Revolut's systems, the attackers allegedly exploited a trusted communication channel to persuade employees to disclose customer information.












