Revolut Hackers Issue $3 Million Ransom for Customer Data

Revolut, UK, neobanks

Hackers claiming to have breached British FinTech Revolut have now reportedly issued a ransom demand.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    Subscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    The group, known as “iamnotavillain,” is threatening to sell confidential information about hundreds of customers unless the online bank pays a roughly $3 million ransom within 24 hours, the Financial Times reported Wednesday (Sept. 16).

    “Revolut has not received any direct contact or demand from the individuals or group making these claims,” the company told th FT. 

    The FT notes that the public demand is unusual, as hackers normally make ransom requests in private, going public only if their target refuses to pay or engage, typically by releasing details of the hack onto the dark web.

    According to the report, the hackers’ message told Revolut to pay 6,000 XMR, or the currency Monero, worth $2.9 million as of early Thursday (Sept. 17).

    If Revolut does not pay, “all the data will be sold, and the blood will be on your hands,” the message said. 

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    Soon after posting the ransom demand, the hackers sent the FT a video clip showing an unseen user combing through the cache of purported Revolut documents, including customer driver’s licenses, passports and identity pictures for know your customer (KYC) verification.

    The data breach, which affected at least 680 customer accounts, happened when the hackers compromised an Italian government email system, the report said. 

    Posing as law enforcement, they were able to demand information on specific Revolut customer accounts over several months, with the goal of targeting “crypto whales” at Europe’s most valuable FinTech, the FT said in an earlier report.

    Revolut has said that its systems and customer funds were not affected by the breach, and that it has notified law enforcement and regulators.

    As PYMNTS wrote Wednesday, this incident, along with a recent outage at the Federal Reserve National Information Center, illustrates an emerging problem for financial institutions.

    “Banks have spent years strengthening their own defenses and scrutinizing their vendors,” that report said. “The next risk perimeter may include the institutions banks are required to trust, something harder to control.”

    That report cited PYMNTS Intelligence data from August showing that 65% of firms plan to adopt or expand identity verification and KYC automation within the next 12 months. 

    Additional data from the PYMNTS Intelligence report “When ‘Good Enough’ Isn’t Enough: Digital Identity Verification in the Age of Bots and Agents” found in January that financial services companies lose close to $34 billion in revenue due to identity verification failures.