Revolut Hit by Fake Email Breach as Hackers Demand $3M Monero Ransom

Revolut confirmed an impersonation scam that exposed data from roughly 700 European clients in September 2026. The iamnotavillain group publicly demanded

Share
Revolut Hit by Fake Email Breach as Hackers Demand $3M Monero Ransom

Editorial illustration for Revolut Hit by Fake Email Breach as Hackers Demand $3M Monero Ransom

Summary

  • Revolut confirmed an impersonation scam that exposed data from roughly 700 European clients in September 2026.
  • The iamnotavillain group publicly demanded 6000 Monero, worth about $3 million, or threatened to sell the records.
  • Multiple ransomware groups have since claimed involvement in the same data breach.

Revolut admitted that criminals tricked staff with fake emails. They stole records from 700 European clients last week. The scam surfaced in September 2026.

The breach exposed Bitcoin activity and passport details. It sparked a $3 million Monero ransom demand right away.

Context

Fintech firms like Revolut hold large volumes of customer records that include crypto transaction histories. Hackers target them often for fast extortion payouts.

The attack relied on forged government emails sent through Italy's certified PEC system. Prosecutors in Reggio Calabria traced the method. Such impersonation tactics bypass standard verification steps when staff process urgent-looking requests.

Details

Euronews reported that hackers stole data belonging to 700 European clients and issued the ransom demand within days of the theft. The group calling itself iamnotavillain set a 24-hour deadline and stated it would sell the records to other criminals if unpaid.

"Revolut confirmed falling victim to an impersonation scam last week."

, The Guardian

Revolut has stated it received no direct contact after the public ransom notice. Multiple additional groups have since claimed responsibility for the same incident, according to Cointelegraph reporting. The company disclosed that the data left its systems after fraudulent requests arrived from an email address mimicking an official source.

The stolen material covers customer passports and Bitcoin-related activity. No evidence has emerged that wallet credentials or account balances were taken.

Outlook

Revolut continues to monitor the situation while law enforcement in Italy reviews the case. Customers are advised to watch accounts for unusual activity and to verify any email requests before sharing documents.