{"id":78273,"date":"2026-09-17T01:28:08","date_gmt":"2026-09-17T01:28:08","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/the-attackers-who-deceived-revolut-now-demand-6000-xmr-bitcoin-news\/"},"modified":"2026-09-17T01:28:08","modified_gmt":"2026-09-17T01:28:08","slug":"the-attackers-who-deceived-revolut-now-demand-6000-xmr-bitcoin-news","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/the-attackers-who-deceived-revolut-now-demand-6000-xmr-bitcoin-news\/","title":{"rendered":"The Attackers Who Deceived Revolut Now Demand 6,000 XMR \u2013 Bitcoin News"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Revolut reportedly sent records on 680 users after criminals posed as officials through a real Italian email system.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">The hacking syndicate dubbed Iamnotavillain demanded 6,000 monero (XMR), about $3 million, after obtaining Revolut customer files. Initially, the hackers demanded BTC.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Revolut disclosed the scam Sept. 12 as investigators examine how the government email channel was abused.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<p>According to the hackers speaking exclusively with <a href=\"https:\/\/www.ft.com\/content\/97f3d2b7-0282-42a7-bbb7-538624441a8a\" target=\"_blank\" rel=\"noopener noreferrer\">the Financial Times (FT)<\/a>, Revolut didn\u2019t lose customer data because hackers cracked its servers. The attackers simply asked for it. Posing as Italian law enforcement for months and using a legitimate government email system, a crew calling itself iamnotavillain spent months requesting files on specific cryptocurrency users.<\/p>\n<p>The hackers\u2019 claims were made to FT reporters Tom Wilson, Laith Al-Khalaf, and Amy Kazmin over \u201ca series of messages.\u201d Revolut allegedly complied with the requests, sending records that included passports, selfies, and transaction histories. Now the group says it has data on about 680 people and wants 6,000 <a href=\"https:\/\/www.bitcoin.com\/price\/monero\/\" target=\"_blank\" rel=\"noopener noreferrer\">monero (XMR)<\/a>, roughly $3 million, while a public countdown clock threatens to turn those identity files over to other criminals.<\/p>\n<h2>They Didn\u2019t Break In. They Asked<\/h2>\n<p><a href=\"https:\/\/news.bitcoin.com\/security\/revolut-leaks-customer-data-to-hackers-posing-as-state-agency\/\">The Revolut data breach<\/a> reportedly worked because the attackers allegedly used Italy\u2019s Posta Elettronica Certificata, or PEC, system, a certified-email network used for legal and government communications. Messages sent through the compromised channel carried genuine domain authentication credentials, so Revolut saw mail that appeared to come from a real government authority.<\/p>\n<p>That was the catch. Authentication could show that an email came from the legitimate domain, but it could not prove the person behind the account was actually an authorized official. Instead of beating Revolut\u2019s security systems, the attackers claim to have exploited the process designed to handle lawful government requests.<\/p>\n<h2>The Victims Were Chosen First<\/h2>\n<p>This was not a random data grab. The group claims it used onchain analysis to identify Revolut users with substantial cryptocurrency activity, then requested records on those people by name. FT\u2019s reporting cited the affected group at about 680 people who leveraged the platform across 31 countries, with many in Switzerland and France.<\/p>\n<p>The files allegedly included names, addresses, phone numbers, account IDs, crypto deposits and withdrawals, fiat transfers, <a href=\"https:\/\/news.bitcoin.com\/security\/as-revolut-attackers-make-threats-heres-how-you-can-lower-kyc-risks\/\">KYC documents, and verification selfies<\/a>. In plain English, the crew was not collecting basic contact information. It was building detailed identity packages on people it believed were worth targeting.<\/p>\n<h2>Then Came the Monero Demand<\/h2>\n<p>On Sept. 16, Iamnotavillain posted a public ultimatum on a website with that very name, demanding <a href=\"https:\/\/www.bitcoin.com\/price\/monero\/\" target=\"_blank\" rel=\"noopener noreferrer\">6,000 XMR<\/a>, framed as roughly $3 million, within 24 hours or the stolen files would be sold to other criminal groups. An earlier <a href=\"https:\/\/www.bitcoin.com\/price\/bitcoin\/\" target=\"_blank\" rel=\"noopener noreferrer\">10,000 bitcoin (BTC)<\/a> demand circulated on Telegram, but the crew later blamed that figure on an impersonator or former associate.<\/p>\n<figure id=\"attachment_848294\" aria-describedby=\"caption-attachment-848294\" style=\"width:1214px\" class=\"wp-caption aligncenter\"><figcaption id=\"caption-attachment-848294\" class=\"wp-caption-text\">Screenshot of the Iamnotavillain website.<\/figcaption><\/figure>\n<p>To many observers, the switch to monero (XMR) makes sense for an extortion demand. Bitcoin transactions are visible on a public ledger, while XMR is designed to obscure transaction details. Revolut, meanwhile, <a href=\"https:\/\/www.irishtimes.com\/business\/2026\/09\/16\/hackers-say-they-breached-italian-state-email-to-target-revolut-crypto-whales\/\" target=\"_blank\" rel=\"noopener noreferrer\">told the press<\/a> that it had received no direct demand from the people claiming responsibility when the countdown appeared, making the clock as much a public pressure campaign as a negotiation.<\/p>\n<p>Revolut maintains that its systems and customer funds were unaffected. The criminals apparently did not penetrate the company\u2019s core network or drain customer accounts. The claim at hand is that they reportedly persuaded Revolut to hand over information through what looked like legitimate official requests.<\/p>\n<p>That does not make the stolen records harmless. A passport, selfie, home address, phone number, and transaction history can support impersonation, account resets, fake support calls, and follow-on attacks against other financial services. The real danger is not only what was taken from Revolut, <a href=\"https:\/\/news.bitcoin.com\/interview\/nexus-id-breach-exposes-a-blueprint-for-fraud-experts-warn\/\">but what those files could unlock elsewhere<\/a>.<\/p>\n<h2>The Bigger Problem Is the KYC Trust Channel<\/h2>\n<p>Revolut <a href=\"https:\/\/techcrunch.com\/2026\/09\/12\/revolut-confirms-customer-data-breach-through-fake-government-requests\/\" target=\"_blank\" rel=\"noopener noreferrer\">told Techcrunch on Sept. 12<\/a> that it had identified the impersonation scam, blocked the address, and notified the relevant agency, law enforcement, and regulators. Investigators are now examining how a legitimate government communications channel became part of the operation.<\/p>\n<p>That leaves an uncomfortable question beyond the digital currency firm itself. If one compromised government mailbox could generate months of convincing information requests, other crypto institutions may have received similar messages. The attackers did not crack the vault. They made themselves look like the people legally allowed to ask for it to be opened.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/crypto-news\/the-attackers-who-deceived-revolut-now-demand-6000-xmr\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways Revolut reportedly sent records on 680 users after criminals posed as officials through a real Italian email system. The hacking syndicate dubbed Iamnotavillain demanded 6,000 monero (XMR), about $3 million, after obtaining Revolut customer files. Initially, the hackers demanded BTC. Revolut disclosed the scam Sept. 12 [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":78274,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/78273"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=78273"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/78273\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/78274"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=78273"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=78273"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=78273"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}