Fintech giant Revolut has confirmed it never received any direct communication from hackers who publicly claimed to have breached its systems, even as separate parties demanded ransoms worth millions of dollars in cryptocurrency.
Competing Ransom Claims
Revolut faced dueling extortion attempts, with one party demanding $3 million in Monero and another seeking 10,000 Bitcoin. The competing claims raise questions about the legitimacy of the alleged breach and whether any actual data was compromised.
Despite the public nature of these demands, the company says the attackers never reached out through any direct channel to negotiate or provide proof of the material they claimed to hold.
No ransom note reached Revolut directly, despite public demands running into the millions.
Skepticism Over the Breach
The choice of Monero as a demanded currency is notable, as the privacy-focused token is favored by cybercriminals for its ability to obscure transaction trails. Bitcoin, by contrast, remains traceable on its public ledger, making the 10,000 BTC demand a curious alternative.
The existence of multiple, competing claimants often signals that opportunists are attempting to capitalize on rumors rather than possessing genuine stolen data. When attackers hold real leverage, they typically establish private contact to prove their claims.
Revolut's position that no direct contact occurred casts doubt on whether the parties making demands actually breached its infrastructure or accessed sensitive customer information.
- One claimant demanded $3 million in Monero
- A separate party sought 10,000 Bitcoin
- Revolut says no attacker made direct contact
The situation underscores the challenges financial firms face in verifying breach claims, where public ransom demands can spread quickly regardless of their authenticity.
