Invest3 publishers3 min readPublished
Hackers priced 680 Revolut customer files at roughly $4,300 each
The group calling itself iamnotavillain wants 6,000 Monero within 24 hours and Revolut says no demand has reached it. The data went out through a government email account the bank was obliged to answer.
The Investor · Invest desk

What happened
- The Financial Times reported on Sept. 16 that a group calling itself iamnotavillain was threatening to sell confidential information on hundreds of Revolut customers unless the bank paid roughly $3 million within 24 hours.
- The records left after the hackers compromised an Italian government email system, and at least 680 Revolut customer accounts were affected.
- The leaked material includes names, dates of birth, home addresses, phone numbers, ID documents, verification selfies, bank statements and transaction lists.
- Revolut told the FT that it has not received any direct contact or demand from the individuals or group making the claims.
- Former Mt. Gox executive Mark Karpeles said he was affected and shared a Revolut notification stating that details about his Bitcoin transactions were revealed, The Block reported.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure The exposure here lands on customers: Chainalysis says victims of violent crypto attacks are commonly identified from leaked data, social media or blockchain analysis before the attack.
- constraint The attackers posed as law enforcement across several months of requests. A platform can no longer treat an official-looking demand as authenticated, and every lawful request now costs verification time too.
- contradiction A public demand with a clock on it means there is no private channel to settle in, so the bank's denial and the attackers' price reach regulators and reporters at the same moment.
- decision With 65% of firms already planning to adopt or expand KYC automation in the coming year, the industry's answer to a compliance-channel breach adds more verified identity data to the same pathways.
Divide the $2.9 million demand across the 680 files and each customer record has been priced at about $4,265 [1]. The demand itself was 6,000 XMR, which implies a Monero rate near $483 [2][2]. Revolut has described the number of affected customers only as "limited", and the 680 figure comes from a single source cited by Reuters [8]. Pricing at that level assumes a buyer who wants particular people, and the on-chain analyst ZachXBT said the targeting looked deliberate: "While the incident is likely limited in size it seems to have been targeted at high net worth users." [16]
The files were taken out through a channel Revolut is obliged to answer. The company says its core systems and client funds were not compromised. An email account on a legitimate government agency's domain was used to submit fraudulent information requests, which Revolut called a "sophisticated external impersonation scam" and blocked once it identified it [11]. The attackers also sent the Financial Times a video clip of someone paging through the cache, driver's licences, passports and KYC identity pictures included [13]. PYMNTS wrote that "The next risk perimeter may include the institutions banks are required to trust, something harder to control." [22]
Reuters reported that Revolut had received no ransom demand or direct contact from the attackers [7], while the message the FT saw ended, "all the data will be sold, and the blood will be on your hands" [5]. Revolut says it has notified law enforcement and regulators [25]. It also holds conditional approval to form a national bank [23], so the supervisors following the coverage are the ones holding that application.
Cryptopolitan frames the fallout as pressure on centralized platforms to secure KYC data, higher compliance costs, and renewed interest in self-custody and privacy [24]. The first two have numbers behind them. On the third, the FCA found that 73% of UK crypto users obtain assets through centralized exchanges [20], and nothing in these reports measures anyone leaving. Self-custody takes the exchange balance out of reach; it does not take back the passport scan, the verification selfie and the home address a platform has already collected [12].
The cost I would expect to recur is request authentication, meaning the people and controls that confirm a police or government demand is genuine before an operations team answers it. The European Banking Authority already ranks cyber risk and data security as the leading operational-risk driver for banks, with fraud second [19]. The counter-case is physical safety, and it has the sharper numbers. CertiK verified 52 physical attacks in the first half, 33 of them in France, about 63% [18][3]. Home invasions rose from one in the first half of 2025 to 20, on a dataset CertiK itself calls indicative [18].
This reading is wrong if the cache is published, the addresses get used, and retail volumes actually move off centralized venues. The FCA's 73% is the baseline to measure that against [20].
What to watch
- Whether Revolut replaces "limited" with a disclosed victim count, and whether it lands above 680.
- Whether the cache appears for sale or on the dark web once the 24-hour deadline lapses.
- Whether European supervisors require platforms to independently verify emergency data requests from government domains.