|
Getting your Trinity Audio player ready...
|
A hacking group calling itself “iamnotavillain” has put a price tag on hundreds of Revolut customers’ personal records — and a ticking clock to match. The group says it will sell the stolen data to other criminals unless the London-based fintech pays $3 million in Monero within a single day.
What makes this stand out isn’t just the number. It’s the method. Most ransomware crews work in the shadows, quietly pressuring victims before going public only when talks stall. This group skipped straight to a countdown timer on a public website, daring Revolut to respond in front of everyone.
How the Breach Happened
According to reporting, the attackers didn’t break through Revolut’s own defenses. Instead, they compromised an Italian government email system and used it to impersonate law enforcement, filing requests for customer account data over several months. It’s a slower, quieter approach than a typical smash-and-grab hack — and one that let them operate largely undetected until now.
The group claims it didn’t grab records at random either. They say blockchain analysis helped them zero in on Revolut accounts holding meaningful crypto balances, narrowing the breach to at least 680 customers rather than casting a wide net.
What’s Reportedly at Stake
Screenshots and a video shared with reporters allegedly show driver’s licenses, passports, KYC verification photos, and transaction histories pulled from the compromised accounts. If genuine, that’s the kind of identity documentation that can enable fraud far beyond a single bank account — a detail likely fueling anxiety among affected users.
Revolut, for its part, says it hasn’t heard directly from the group and has found no contact or ransom demand addressed to the company. The bank has told customers it’s offering support and working with law enforcement, but the public nature of this threat leaves little room for a quiet resolution.
Why the Public Ultimatum Matters
Also Read: CoinEx Shuts Down After 9 Years — Is Your Coin One of the 37 Frozen?
Demanding Monero — a privacy coin built to resist transaction tracing — is standard practice for cybercriminals looking to cash out without leaving a paper trail. But broadcasting the demand on a branded website, complete with a live countdown, is a pressure tactic aimed as much at public opinion as at Revolut’s negotiators. It forces the company to respond under scrutiny rather than behind closed doors.
For a company valued at $115 billion and serving 80 million customers across more than 30 countries, the reputational stakes may end up mattering as much as the ransom figure itself.
The Bottom Line
Whether Revolut pays, stalls, or calls the bluff, the clock the hackers set is already doing its job — turning a data breach into a very public test of how a major fintech handles a crisis in real time.
Disclaimer: The information in this article is for general purposes only and does not constitute financial advice. The author’s views are personal and may not reflect the views of Chain Affairs. Before making any investment decisions, you should always conduct your own research. Chain Affairs is not responsible for any financial losses.
