Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$76,483▲ 1.28%ETH$2,432▲ 1.62%SOL$99.31▲ 2.84%TOTAL CRYPTO$2.63T▼ 1.40%S&P 5007,551.81▼ 3.00%NASDAQ25,978.42▼ 2.81%DOW51,461.90▼ 4.23%GOLD4,353.20▼ 2.69%WTI102.22▲ 20.97%BRENT105.86▲ 16.50%EUR/USD1.1461▼ 0.98%USD/JPY156.14▼ 1.94%DXY100.31▲ 0.67%
Crypto

Revolut Hackers Demand $3 Million in Monero Ransom

The group gave Revolut 24 hours to pay and said it targeted customers with significant crypto holdings.

Pexels – Alesia Kozik

Hackers holding data stolen from Revolut are demanding $3 million in Monero and gave the British fintech 24 hours to pay, threatening to sell customer records with a stated focus on clients who hold large amounts of crypto.

The demand surfaced on Wednesday, according to CoinDesk, which reported that the group set a hard deadline and said it had deliberately selected customers with significant crypto holdings as its priority targets. Revolut has not confirmed the size or scope of any breach in a public statement so far, and the company’s press office has not responded to requests for comment on whether negotiations are underway.

Crypto holders in the crosshair

The stated targeting logic matters as much as the ransom number. Extortion crews have learned that a leaked passport scan or address file is worth little on its own, but the same record attached to a person known to hold bitcoin or ether is a kidnapping risk, a phishing kit and a SIM-swap lead all at once. By naming crypto-rich customers, the group is trying to raise the perceived cost of refusing to pay.

Revolut serves tens of millions of customers across Europe and beyond and has become one of the main on-ramps through which retail users buy bitcoin and stablecoins. A database that links identity documents to trading activity is, in practice, a map of who owns what, and security researchers have warned for years that exchange and neobank leaks function as target lists for violent and non-violent attacks alike.

The group gave Revolut 24 hours to pay and said it targeted customers with significant crypto holdings, according to CoinDesk.

Why Monero

The choice of Monero is standard for criminal extortion and hard to argue with from the attackers’ point of view. Bitcoin transactions are traceable on a public ledger, and exchanges with strong compliance teams freeze identified stolen funds regularly. Monero’s privacy design obscures sender, receiver and amount, which is why ransomware groups migrated to it years ago and why law enforcement agencies keep pressing exchanges to monitor for XMR cash-outs tied to known cases.

A $3 million ask is modest by the standards of large corporate extortion, where demands routinely run into eight figures. That pricing suggests the sellers believe the data has a ready resale market even if Revolut refuses, which keeps pressure on the company regardless of whether it negotiates. Ransomware economics have shifted in this direction for years: the initial demand is often less valuable than the follow-on sale of the same data to fraud networks, which operate at industrial scale and buy verified identity files by the batch.

What Revolut faces now

The company has been here before in a smaller way. In 2022 a social engineering attack on a third party exposed personal data of a portion of its customers, an incident Revolut disclosed and regulators in Lithuania reviewed. The difference this time is the explicit monetization threat and the crypto angle, which turns a privacy incident into a physical-safety concern for the customers named.

For Revolut’s crypto business specifically, the reputational math is unforgiving. The company has been expanding licensed crypto services in the EU under the Markets in Crypto-Assets regime, a framework that leans heavily on the idea that regulated platforms protect customer data better than offshore exchanges. An extortion case that ends with customer lists on a leak site undercuts that pitch at exactly the moment banks and neobrokers are competing for the same users.

Regulators will also want answers on how the data left. If the exfiltration came through a vendor or an insider rather than Revolut’s own perimeter, the incident still lands on the company’s plate under GDPR, which treats customer data breaches as reportable events with tight deadlines. The UK’s Information Commissioner’s Office and Lithuania’s central bank, which licenses Revolut’s EU banking entity, are the likely first stops for questions.

The verification problem

Whether the group actually holds what it claims is the other open question. Extortion demands routinely inflate stolen datasets, and security researchers have documented cases where ransom notes accompanied by small sample files turned out to cover data scraped from public sources. Until Revolut confirms the breach or the data appears on a leak site, the $3 million figure is a claim, not a verified fact.

The 24-hour deadline has almost certainly expired or will expire before any outcome is public. Companies that pay rarely say so, and companies that refuse usually say nothing until the leak hits. Either way, the case adds to a growing pattern in which crypto wealth itself, not just exchange infrastructure, is treated as the target.

The wider industry has seen this script before. Ledger, the French hardware wallet maker, suffered a 2020 customer database breach whose fallout included phishing campaigns and even reported home visits years later. Coinbase disclosed in 2025 that criminals had bribed overseas support contractors for customer data, then used it in social engineering attacks that produced eight-figure losses among targeted users. Both cases show the same chain: identity data first, crypto losses second.

For Revolut customers, the practical advice security firms give in these situations is unchanged. Treat unsolicited contact about your account as hostile, expect convincing phishing that references real account details, and assume any phone number or email tied to your profile is already in someone’s database. The company’s own security page has so far offered no guidance specific to this incident.

How the group obtained the data remains unclear. The most common routes in recent fintech incidents are compromised third-party vendors, credential theft from contractors with support access, and infostealer malware on employee machines. Each route implies a different fix and a different regulatory conversation, which is why the eventual incident report will matter more than the ransom number itself.

SourcesCoinDesk; Reuters; Financial Times; BleepingComputer.
Share: X