THE TELL

Revolut handed customer passports to fake officials. Now someone wants 6,000 monero for them

Nobody picked a lock. Someone wrote to Revolut pretending to be a government official, asked for customer records, and got them.

The requests looked official. They passed Revolut's checks. The company handed over customer records and only afterwards discovered the requests were fraudulent, according to notices it had sent to affected customers. At least 680 accounts were affected.

Now a group calling itself "iamnotavillain" is asking for money. It wants $3 million worth of monero — 6,000 XMR, a coin built to hide who sent what to whom — within 24 hours, and it posted the demand on Wednesday with a countdown clock running, the Financial Times reported. If Revolut doesn't pay, the group says it will sell the data to other criminal groups. To show it has the goods, it sent the FT a 60-second screen recording: passports, driving licences, the selfie photos used for identity checks, transaction histories.

What it means

The detail that should make you sit up isn't the ransom. It's how the victims were chosen. The hackers told the FT they used blockchain analysis to find Revolut accounts with significant crypto holdings. In plain terms: they read the public ledger, saw which wallets held real money, and then went looking for the names behind them. The blockchain is public by design — that was always the selling point. Here it worked as a shopping list.

A stolen coin can be moved, frozen, sometimes even returned. A passport scan cannot be un-copied. That's the whole story in one line, and it's why this breach is different from the exchange hacks people are used to reading about.
Share this

Revolut has said its systems and customer funds were unaffected, that it blocked the address used in the requests, and that it notified the relevant government agency, law enforcement and regulators. All of that can be true at once and still leave 680 people in a bad spot. Their money is fine. Their identity documents are in a video being shown to journalists as proof of sale. The weak point here wasn't code — it was a human being reading an email that looked official enough.

Who it matters to

Anyone who has ever uploaded a photo of their passport and a selfie to open an account on their phone — which is most people under 40 who use a fintech app, and pretty much everyone who has touched crypto legally. Especially the ones with a few thousand in coins and no idea their wallet activity is readable by strangers: that visible balance is what got some of these 680 accounts picked out. It also touches anyone weighing whether to keep savings in an app rather than a traditional bank: the app didn't lose the money, it lost the documents, and those are the ones you can't replace with a new card.

What's next

The countdown was 24 hours from Wednesday. What happens when it runs out, we don't know: the hackers told the FT there had been no negotiations with Revolut at the time of publication, and Revolut did not respond to CoinDesk's request for comment by publication. Watch for two things — whether Revolut says anything about paying or refusing, and whether the government agency it notified says anything at all. No deadlines have been named for either.

One detail to hold on to

The attackers didn't break Revolut. They asked it, in the voice of a government, and it answered. Somewhere in that exchange a person decided the request looked legitimate enough to act on. That decision is now 680 passports long — and no amount of monero buys it back.

Sources: CoinDesk, September 16, 2026, reporting on the Financial Times.

Why we ran this8/10

Мошенники притворились госорганом, Revolut сам отдал им паспорта и селфи клиентов, а теперь взломщики по блокчейну выбрали тех, у кого больше крипты, и требуют выкуп — украденную личность, в отличие от монет, вернуть нельзя.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← Revolut handed customer passports to fak…Next: A model needed a number it couldn't find. … →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X