A cyberattack targeting the neobank Revolut has reached a critical stage following threats issued by a hacker group known as "iamnotavillain." The perpetrators are demanding 6,000 Monero (XMR)—equivalent to approximately $3 million—threatening to leak the personal data of 680 high-net-worth clients on the dark web if their demands are not met. Unlike a traditional server breach, the attackers exploited a procedural loophole by impersonating Italian government authorities to secure confidential information directly from the institution's compliance department through fraudulent data requests.
The modus operandi reveals a concerning level of ingenuity rooted in on-chain analysis. The hackers scrutinized public blockchain ledgers to identify Revolut accounts linked to substantial crypto wallets, effectively targeting high-value profiles. The compromised data includes sensitive documents such as passports, driver's licenses, and full transaction histories obtained through KYC verification procedures. While the bank’s internal infrastructure and user funds do not appear to have been technically compromised, this leak exposes the victims to significant risks of extortion, phishing, and identity theft.
Facing this ultimatum, Revolut maintains a firm stance, emphasizing its cooperation with the relevant authorities. Management asserts that it has not received a direct ransom demand, highlighting the atypical nature of this approach, as the hackers chose to publicize the threat rather than negotiate privately. The choice of Monero as the currency of exchange is no coincidence: this cryptocurrency, known for its advanced privacy features, makes tracking financial flows extremely difficult for law enforcement, further illustrating the sophistication of modern cybercriminal methods.
This incident raises crucial questions regarding the verification protocols for legal requests within rapidly growing fintech firms. As Revolut boasts an impressive valuation and a massive global user base, client trust now hinges on the company's ability to secure its data management processes against hybrid attack vectors. As the countdown nears its end, monitoring illicit markets has become a priority, while platform users are urged to exercise heightened vigilance regarding any suspicious communication.