Hackers Demand $3 Million Ransom From Revolut
British fintech Revolut disclosed customer information after fraudulent data requests were sent from an email account on a legitimate Italian government domain. The incident did not involve a direct intrusion into Revolut’s core systems, but exposed identity documents, contact details, IBANs, account statements and transaction histories. The case is significant because it shows how attackers can exploit trusted channels to bypass institutional controls, a growing risk for fast-expanding digital banks holding both financial and know-your-customer records.
On Sept. 16, 2026, the group iamnotavillain demanded $3 million in Monero and gave Revolut 24 hours to pay, threatening to sell confidential records to other criminal groups. Reports said about 680 customers were affected, with some apparently selected for substantial cryptocurrency holdings. Revolut said customer funds and internal systems remained unaffected. The company said it had blocked the email source, contacted affected clients and notified law-enforcement, data-protection and financial regulators.
All Coverage
2 original reportsThe Backstory
The history behind this eventRevolut Data Leak Exposes Security Gaps Beyond Fines
Revolut’s mobile-first model has helped it reach more than 80 million customers and operate as a bank in over 30 countries, concentrating identity, account and transaction data in a fast-growing platform. The risk is not new: a September 2022 social-engineering attack exposed data tied to 50,150 customers worldwide, including 20,687 in the European Economic Area. The repeated failures sharpen concern that regulatory penalties alone cannot correct weaknesses in verification, access controls and security governance.
On Sept. 11-12, 2026, Revolut notified affected customers that it had fulfilled fraudulent information requests sent from an unauthorized mailbox inside an official government domain. The messages carried valid domain-authentication credentials; records disclosed may have included passports, verification selfies, IBANs, withdrawal data and full transaction histories, including Bitcoin activity. Revolut said its systems and customer funds were unaffected, but did not disclose the number of people involved. The Bank of Lithuania’s separate €3.5 million anti-money-laundering fine on April 8, 2025, underscores how sanctions have yet to dispel broader control concerns.
Revolut Rejects Claim of 75 Million-Customer Data Breach
Revolut, a UK-based fintech company offering banking and payment services through its mobile app, has a large customer base that makes any alleged data exposure a significant cybersecurity concern. Listings of financial records on dark-web forums can raise the risk of fraud and identity theft, while also testing customer confidence and drawing scrutiny of a company’s data-protection controls.
As of Aug. 3, 2026, a hacker claimed to be selling 75 million purported Revolut customer records on the dark web for $500. Revolut said it compared and validated the material and found no evidence that its systems had suffered a data breach. The company concluded that the dataset was highly likely to have been fabricated rather than obtained from genuine customer records.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →