Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background
    Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Revolut Hackers Cut Ransom to $3M, Set 24-Hour Deadline to Sell 680 Customer Files: FT

The ransom pivot from Bitcoin to Monero could make the hackers’ payment trail much harder for investigators to follow.

Written By Dishita Malvania
Published 54 minutes ago·Updated 52 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Hooded hacker targeting Revolut on laptop surrounded by monitoring displays.
AI Summary
Show
IAmNotAVillain demands ~6,000 XMR ransom, 24‑hour deadline, using privacy‑coin to evade blockchain tracing.
Attack leveraged compromised government PEC mailbox, passing SPF, DKIM, DMARC checks, tricking Revolut’s compliance workflow.
Breach exposed 680 customers’ passports, IDs, IBANs, and full Bitcoin transaction histories, enabling targeted extortion.

The threat actor known as IAmNotAVillain has issued a fresh demand and a countdown clock, a sharp climbdown from the 10,000 Bitcoin figure that circulated on Telegram over the weekend, with researchers tracking the leak site pointing to Monero as the requested payment.

Hackers behind the September customer-data disclosure at British fintech Revolut have issued a new ransom demand of about $3 million (reported as 6,000 XMR), payable within 24 hours, or the confidential records of hundreds of customers will be sold to other criminal groups. 

The fresh figure marks a steep reduction from the 10,000 Bitcoin (BTC) headline that circulated on Telegram over the weekend, and researchers tracking the leak site say the payment is being sought in Monero (XMR), a privacy-focused cryptocurrency built to obscure sender, receiver and transaction amount.

The Financial Times (FT) reported on Wednesday that the operators behind the breach threatened to sell the records of hundreds of customers to other criminal groups unless the London-based fintech pays the ransom inside the 24-hour window. A person familiar with the matter told the FT, in reporting republished by the Irish Times, that Revolut had not been contacted by the perpetrators and was yet to receive a ransom demand through a negotiated channel, a distinction that can sit alongside a public countdown on the actor’s own leak site.

What Changed on Wednesday

The Crypto Times previously reported that Revolut’s compliance team accepted a fraudulent information request sent from an authenticated government mailbox. Revolut first notified affected customers on 12 September 2026; the company and later reporting say the impersonation emails ran for months before that date, exposing identity documents, passport and driving licence copies, verification selfies, contact details, International Bank Account Numbers (IBANs), account statements, withdrawal records and full transaction histories including Bitcoin activity. 

What is new on 16 September 2026 is the size, speed and payment vehicle of the demand: smaller in dollar terms, faster in deadline and denominated in a privacy coin rather than Bitcoin.

The change of payment rail is not incidental. Bitcoin is transparent on-chain, and every investigator watching this file, from Britain’s data-protection regulator to European law-enforcement units, would follow a 10,000 BTC payment across exchanges within hours. Monero is designed to defeat that tracking, which is why the request now sits there.

Who The Actor Is And What It Has Said

The demand is attributed to a threat actor operating under the handle IAmNotAVillain, whose clearnet site iamnotavillain.xyz appeared earlier this week before being taken down, according to researchers monitoring the case. Infrastructure was quickly restored on a replacement domain carrying a countdown timer. 

In messages sent, the group claimed the operation ran for months from Italy and used a compromised government mailbox to target “crypto whales,” selected through on-chain analysis of Revolut accounts with significant crypto holdings. Most of the 680 sit in Switzerland and France, with the rest spread across 31 other mainly European countries including the United Kingdom, Germany and Spain, according to the actor’s messages to the FT. Those country shares have not been independently confirmed by Revolut. 

Italian outlets reporting the same Wednesday demand also say the actor claims to hold about 147 GB of Italian law-enforcement files. That claim is unverified; Italian authorities have not confirmed a breach of police systems.

Readers who saw the story over the weekend may recall a demand of 10,000 BTC, roughly $780 million at mid-September prices. That figure was tied to a competing brand calling itself Revolut Smilik. IAmNotAVillain has since said an impersonator who was given a data sample is falsely taking credit for the wider breach. Until Revolut or a regulator confirms otherwise, both the 10,000 BTC and $3 million figures remain threat-actor speech; only the underlying disclosure is a company fact.

The Regulatory Track

The United Kingdom’s Information Commissioner’s Office (ICO) said it had received a report and was assessing it, and the Financial Conduct Authority (FCA) said it was engaging with the firm. As The Crypto Times reported on 15 September 2026, the 680 total includes 12 customers in Ireland, 25 in Spain and 27 in Romania on the national slices then on the record, drawn from reporting by RTÉ, El Español and Profit.ro. 

Revolut Bank UAB in Lithuania remains the European banking entity supervised by the European Central Bank (ECB) and the Bank of Lithuania, and is the legal-request desk that matters in this case rather than the consumer app.

The Italian Angle

Revolut has not named the identity of the impersonated agency. Italian coverage and the FT’s own reporting point to Italy’s La Posta Elettronica Certificata (PEC) system, the government-overseen certified-email network used for official correspondence, with the specific mailbox tied to Italy’s Ministry of Interior. Some Italian reporting has named a Reggio Calabria prefecture PEC address; Revolut has not confirmed the mailbox.

Italian postal police, state police, the interior ministry and the national cybersecurity agency all declined to comment on the record, although officials confirmed to the FT that investigations were under way. Italian opposition lawmaker Giulia Pastorella has asked the interior ministry for an explanation.

What Is At Stake For The 680

The bundle in circulation pairs passport and driving-licence copies with verification selfies, IBANs, statements and full Bitcoin transaction histories. That combination gives an attacker a legal name, a face, a recovery path and a chain-analysis starting point, a materially different object from a standard email-and-password dump. 

No private keys, card personal identification numbers (PINs) or account balances were listed in Revolut’s notice, and no customer-fund theft has been reported. The residual risk lies in targeted extortion of the 680 and account-recovery social engineering, not a run on the app.

What Revolut Has Said

Revolut said that it had identified a “sophisticated external impersonation scam” in which an unauthorised third party used a mailbox on a legitimate government agency domain to submit fraudulent requests for information. 

The messages passed Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC) checks, so compliance staff processed them as they would a routine legal demand. The company then blocked the address, alerted the impersonated agency, and notified law enforcement, data-protection authorities and financial regulators. Revolut has said its systems and customer funds were unaffected.

This is a developing story. The next facts that would move it are a public Revolut response to the $3 million demand, a named agency from London or Rome, or a regulator filing that treats the legal-request desk as the control failure rather than the mailbox as an isolated curiosity.

Also Read: Blockaid Flags FlamingoFinance Contract Exploit, $345.9K Stolen

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Cryptocurrency
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Ledger CTO Reviews SHRINCS Bitcoin Signature Proposal
Ledger CTO Reviews SHRINCS Bitcoin Signature Proposal
Lummis Challenges Alsobrooks After CLARITY Act Vote Fails
Lummis Challenges Alsobrooks After CLARITY Act Vote Fails
Official speaking into microphone with open hands at a hearing desk behind a nameplate reading "N W. KIRK".
Paul Atkins Says SEC Will Pursue Crypto Rules After CLARITY Act Setback
Physical Bitcoin, Ethereum, and XRP coins resting in front of a declining market chart and the Federal Reserve building.
Crypto Market Turns Red as CLARITY Act Setback Meets Fed Rate Decision
Government official seated at a committee table with hands clasped.
CFTC Chair: Americans Deserve Crypto Clarity After Senate Vote Fails 49–50

Find Us on Socials

You may also like

Hand holding smartphone displaying the Ondo Finance logo in front of DTCC wall signage.

DTCC Adds Ondo’s Oasis Pro Markets to Fund/SERV Network 

Flamingo Finance logo displayed over a gradient purple background.

Blockaid Flags FlamingoFinance Contract Exploit, $345.9K Stolen

Physical Bitcoin coin positioned in front of a Glassnode sign and rising line chart.

Bitcoin Falls Below $76.7K True Market Mean as Demand Weakens 

Deutsche Bank gold lettering mounted on a stone building facade.

Deutsche Bank to Launch Bitcoin and Ether Custody Service in Europe

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information