Revolut Hackers Seek $3M Monero Ransom, Threaten Data Sale
A threat group claims it targeted Revolut customers with large crypto balances by scanning blockchain activity, then demanded a $3 million ransom in Monero and threatened to sell stolen data. The incident underscores how on-chain visibility can aid victim selection while privacy coins remain a preferred payment rail for extortion.
A threat group has claimed responsibility for a data-extortion attempt involving Revolut customers, according to a report cited in the original signal. The group allegedly demanded a $3 million ransom in Monero and threatened to sell customer data if the payment was not made.
The attackers said they selected targets by scanning the blockchain for Revolut accounts holding significant cryptocurrency balances. If accurate, that method would suggest a more targeted approach than broad phishing or indiscriminate malware campaigns, with attackers using public transaction data to identify higher-value victims.
The reported demand in Monero is notable because privacy-focused cryptocurrencies are often used in extortion cases to reduce traceability. For financial institutions and crypto platforms, the episode reinforces a familiar risk: even when custody systems are not directly breached, customer exposure can still become a liability through account-level intelligence, social engineering or third-party compromise.
Revolut has not been the subject of a confirmed, large-scale platform breach in the material provided here, and the claims remain unverified in this signal. Still, the allegation is consistent with a broader pattern in which attackers combine blockchain analytics, leaked credentials and data theft to pressure victims into fast settlement.
For users, the practical takeaway is straightforward: on-chain transparency can improve market integrity, but it can also help criminals identify wallets with outsized balances or active trading behavior. That makes operational security, address hygiene and account monitoring increasingly important for retail and institutional participants alike.
Market Telemetry & Impact
Algorithmic Transparency & E-E-A-T ComplianceAutomated Fact-Checking
This intelligence report is generated and verified by the Squaby Algorithmic Fact-Checking Engine without manual human intervention. It strictly isolates on-chain risk vectors, market liquidity data, and OSINT sentiment streams. All data is processed for institutional clarity and educational purposes only. This content does not constitute financial or investment advice.
Deconstruct Early-Stage Web3 Token Audits & Vesting Cliffs
Learn to evaluate on-chain liquidity locks, contract audit ratings, and founder KYC verifications.