A group calling itself iamnotavillain demanded about $3 million in Monero after claiming access to Revolut customer data, according to Financial Times reporting also covered by CoinDesk. Reports say roughly 680 customer accounts were affected. Revolut said core systems and funds were unaffected and that it did not receive a direct ransom demand.

The group reportedly asked for about 6,000 XMR within 24 hours and threatened to sell the data if unpaid. According to the same reporting, the exposed material may include identity documents, KYC selfies, and transaction histories. The data was obtained through fraudulent requests sent via a legitimate government email domain, not by breaking into Revolut’s core banking stack.
Revolut has said customer funds and core systems were unaffected. It also said it did not receive a direct ransom demand from the group, even as third-party reporting described the Monero demand and the threat to sell customer information.
Centralized finance apps still collect identity files that can become valuable to thieves when those files leave the intended channel. Privacy matters because a warehouse of sellable ID documents is an attractive target.
Serey respects privacy and aims not to hold a warehouse of sellable identity files. That design choice reduces what a breach can harvest, but it is not an absolute guarantee that hacking would yield nothing. Users should still treat identity and account access with care.
