Hackers who claim responsibility for a data breach at fintech giant Revolut are demanding a $3 million ransom paid in the privacy coin Monero, threatening to sell sensitive customer information if the company fails to comply within 24 hours. Revolut has stated it has received no direct communication from the group.
The Ransom Demand
The group behind the alleged breach issued a tight deadline, giving Revolut just 24 hours to meet their financial terms. Their choice of Monero as the payment method is notable, as the privacy-focused cryptocurrency is designed to obscure transaction details, making it far harder to trace than assets like bitcoin.
According to the attackers, the breach specifically targeted Revolut users holding substantial cryptocurrency balances. That focus suggests the hackers may be seeking to maximize the value of the stolen data, whether through direct extortion or by selling the information to third parties.
Pay within 24 hours in untraceable Monero, or the customer data goes up for sale.
Revolut's Response
Revolut has pushed back on aspects of the situation, saying it has not been contacted directly by the individuals claiming responsibility. That leaves questions about the scope of the incident and whether the company can independently verify the attackers' claims.
For customers, the reported targeting of accounts with large crypto holdings raises immediate security concerns. Users are typically advised to remain vigilant against phishing attempts and unauthorized access following any suspected breach.
Key details of the incident include:
- A $3 million ransom demanded in Monero
- A 24-hour window to comply
- Customers with significant crypto holdings allegedly targeted
- Revolut says it received no direct contact from the group
The episode underscores the growing threats facing fintech platforms that manage both traditional and digital assets, where the concentration of high-value crypto holdings can make certain customers especially attractive targets for cybercriminals.
