Key highlights:
- Hackers demanded 6,000 XMR from Revolut after exploiting an Italian government email domain to submit fraudulent law enforcement data requests
- Italian prosecutors in Reggio Calabria and the National Anti-Mafia Directorate have opened investigations into how the government email account was compromised
- Chainalysis estimates violent crypto “wrench attacks” have already stolen $30M+ in 2026, with home invasions rising from 26% to 37% of documented attacks
A data breach at Revolut has exposed a deeper problem for crypto users than a stolen password or compromised wallet. The attackers appear to have exploited trust between a financial institution and a government agency, obtaining sensitive customer information that can potentially be used for targeted fraud and social engineering.
A group calling itself “iamnotavillain” has now demanded $3 million in Monero from British digital bank Revolut, threatening to sell the information it claims to have obtained to other criminal groups if the fintech does not pay within 24 hours.
Revolut says hackers exploited a government email scam, not its own systems
Hackers claiming responsibility for the Revolut data leak have demanded 6,000 XMR, worth about $3 million, after publishing the alleged stolen information on their website alongside a countdown clock.
The group reportedly went public before attempting to negotiate with Revolut, an unusual approach in extortion cases, according to the Financial Times, which contacted the hackers through Telegram.
They provided screenshots and a 60-second screen recording that appeared to show documents allegedly taken from Revolut.
The material reportedly included passports, driving licenses, identity photographs used for customer verification, and transaction records.
The hackers claimed to have obtained 147 gigabytes of data, although the size and contents of the alleged cache have not been independently verified.
‼️ BREAKING: The threat actors who targeted Revolut with information-demand emails are now posting sensitive customer data, including that of high-profile clients such as tennis player Shevchenko and Römer, CEO of Gamdom/Skinscom.
They want Revolut to pay up. They say they’ll… pic.twitter.com/obuVOOABx7
— International Cyber Digest (@IntCyberDigest) September 13, 2026
Revolut has confirmed that customer information was disclosed to an unauthorized third party but said the incident was not caused by a breach of its own systems.
Instead, the company described it as an external impersonation scam in which attackers used a legitimate Italian government email domain to submit fraudulent requests for customer data.
The hackers posed as an Italian “law enforcement agency” and said that Revolut “cooperated like a ‘good guy.'”
Revolut employees processed the requests because the emails carried valid domain authentication credentials and appeared to be genuine government communications.
Investigators are now examining how the attackers gained access to the government email system and whether an account was compromised, cloned, or otherwise misused.
Italian prosecutors in Reggio Calabria have opened an investigation because the email account was linked to a government institution in the region. Italy’s National Anti-Mafia and Counter-Terrorism Directorate is also involved, while the country’s data protection authority has begun checks with financial institutions.
What data was exposed in the Revolut leak?
The incident reportedly affected about 680 European Revolut customers, although the final number remains under investigation.
Notification emails reviewed by TechCrunch indicated that exposed records could include names, dates of birth, occupations, addresses, phone numbers, and email addresses, as well as passport or driving license copies and facial verification images.
Some records reportedly contained account statements, IBANs, wallet references, withdrawal records, and transaction histories, including Bitcoin activity.
Revolut said customer funds and core systems remain unaffected. It also said login credentials, card PINs, and passcodes were not exposed, with no evidence of direct account takeovers.
The potential danger extends beyond criminals gaining access to a Revolut account.
A passport, home address, phone number, and crypto transaction history can provide enough information to identify wealthy crypto holders and make impersonation attempts more convincing.
Why exposed Revolut data could become a serious security threat for crypto users
That leaked information can also create a pathway to a more serious threat commonly known as “wrench attacks,” in which criminals use physical violence, threats, kidnapping, or home invasions to force victims to surrender crypto.
Chainalysis links the surge in wrench attacks partly due to criminals having access to this kind of information, including names, addresses, phone numbers, and holdings.
Chainalysis estimates that violent crypto attacks have already resulted in more than $30 million in stolen funds in 2026, after reaching a record $58 million in 2025.
Home invasions accounted for 37% of documented attacks through mid-2026, up from 26% in 2023.
The Ledger customer data breach in 2020 illustrates why exposed information can remain a security risk long after an incident.
The leak exposed about 1.1 million email addresses and was later linked to phishing, extortion attempts, and reports of physical threats against crypto holders.
The Revolut incident is different because it reportedly involved the exploitation of a legitimate law-enforcement communication process rather than a direct breach of the fintech’s systems.
But the potential consequence is sensitive information falling into the wrong hands can help criminals identify, profile, and target crypto holders.
Source:: Revolut Hackers Demand $3M in Monero After Data Breach