How did hackers steal Revolut customer records for a 6,000 XMR ransom demand?

Hackers obtained sensitive Revolut customer records by submitting fraudulent official data requests to the company, leading to a ransom demand of 6,000 Monero (XMR). This security failure has triggered an immediate investigation by Italian data protection authorities into the fintech’s verification processes.

Hackers successfully compromised the records of hundreds of Revolut customers by using fraudulent official data requests to bypass standard security protocols. By impersonating law enforcement agencies, the attackers convinced the platform to release sensitive user information, subsequently demanding a ransom of 6,000 Monero (XMR)—worth roughly $3 million—to prevent the release of the stolen data. This breach highlights a growing vulnerability where cybercriminals exploit the legal channels used by authorities to request emergency data.

In response to the incident, Italy’s data protection regulator, the Garante, has opened a formal probe to investigate how these fraudulent requests were authenticated. The investigation will focus on whether Revolut maintained adequate safeguards to distinguish between legitimate law enforcement inquiries and sophisticated social engineering attacks. This case is particularly significant for US-based fintech users, as it exposes a systemic weakness in how global digital banks handle 'emergency' requests that often bypass traditional judicial oversight.

The choice of Monero for the ransom payment underscores the persistent regulatory friction surrounding privacy coins. Because XMR offers stealth addresses and ring signatures that obscure transaction details, it remains the primary tool for extortionists seeking to evade blockchain analysis. This event is likely to provide further ammunition for regulators in the US and EU who are pushing for stricter controls or outright bans on privacy-centric assets to combat money laundering and cybercrime.

Moving forward, investors and users should watch for potential fines against Revolut and a possible shift in how fintech companies verify legal requests. There is also a high likelihood that this breach will lead to renewed calls for the 'Travel Rule' to be more strictly applied to unhosted wallets and privacy-enhancing technologies. Readers should remain vigilant against phishing attempts that may follow such a data leak, as stolen records are frequently used to target individuals in secondary crypto-theft campaigns.

Editorial method

This report is based on the linked source and is labeled with its publication date, provider, category and market-impact assessment. Market interpretation is informational, not investment advice.