Revolut handed customer passports to fake officials. Now someone wants 6,000 monero for them
Nobody picked a lock. Someone wrote to Revolut pretending to be a government official, asked for customer records, and got them.
The requests looked official. They passed Revolut's checks. The company handed over customer records and only afterwards discovered the requests were fraudulent, according to notices it had sent to affected customers. At least 680 accounts were affected.
Now a group calling itself "iamnotavillain" is asking for money. It wants $3 million worth of monero — 6,000 XMR, a coin built to hide who sent what to whom — within 24 hours, and it posted the demand on Wednesday with a countdown clock running, the Financial Times reported. If Revolut doesn't pay, the group says it will sell the data to other criminal groups. To show it has the goods, it sent the FT a 60-second screen recording: passports, driving licences, the selfie photos used for identity checks, transaction histories.
The detail that should make you sit up isn't the ransom. It's how the victims were chosen. The hackers told the FT they used blockchain analysis to find Revolut accounts with significant crypto holdings. In plain terms: they read the public ledger, saw which wallets held real money, and then went looking for the names behind them. The blockchain is public by design — that was always the selling point. Here it worked as a shopping list.
A stolen coin can be moved, frozen, sometimes even returned. A passport scan cannot be un-copied. That's the whole story in one line, and it's why this breach is different from the exchange hacks people are used to reading about.
Revolut has said its systems and customer funds were unaffected, that it blocked the address used in the requests, and that it notified the relevant government agency, law enforcement and regulators. All of that can be true at once and still leave 680 people in a bad spot. Their money is fine. Their identity documents are in a video being shown to journalists as proof of sale. The weak point here wasn't code — it was a human being reading an email that looked official enough.
Anyone who has ever uploaded a photo of their passport and a selfie to open an account on their phone — which is most people under 40 who use a fintech app, and pretty much everyone who has touched crypto legally. Especially the ones with a few thousand in coins and no idea their wallet activity is readable by strangers: that visible balance is what got some of these 680 accounts picked out. It also touches anyone weighing whether to keep savings in an app rather than a traditional bank: the app didn't lose the money, it lost the documents, and those are the ones you can't replace with a new card.
The countdown was 24 hours from Wednesday. What happens when it runs out, we don't know: the hackers told the FT there had been no negotiations with Revolut at the time of publication, and Revolut did not respond to CoinDesk's request for comment by publication. Watch for two things — whether Revolut says anything about paying or refusing, and whether the government agency it notified says anything at all. No deadlines have been named for either.
The attackers didn't break Revolut. They asked it, in the voice of a government, and it answered. Somewhere in that exchange a person decided the request looked legitimate enough to act on. That decision is now 680 passports long — and no amount of monero buys it back.
Sources: CoinDesk, September 16, 2026, reporting on the Financial Times.
Мошенники притворились госорганом, Revolut сам отдал им паспорта и селфи клиентов, а теперь взломщики по блокчейну выбрали тех, у кого больше крипты, и требуют выкуп — украденную личность, в отличие от монет, вернуть нельзя.
Written by THE TELL’s AI newsroom. how we work · corrections