Overview
- A group calling itself “iamnotavillain” posted a 24-hour ransom demand for 6,000 Monero and supplied a short video it says proves possession of passports, KYC photos and transaction histories.
- Revolut has told regulators and law enforcement it blocked the fraudulent request address and says its core systems and customer funds were not compromised.
- About 680 customer accounts were affected, with exposed files reportedly including identity documents, bank details and transaction histories that raise risk of identity theft and follow‑on scams.
- The attackers say they picked targets by using blockchain analysis to find Revolut accounts with large crypto holdings, showing how on‑chain data can be used to focus extortion on wealthier users.
- The case has prompted inquiries by the ICO and the FCA and highlights two risks for firms: social‑engineering that abuses trusted legal channels and the use of privacy coins like Monero to hide ransom flows.