- A group claiming to hold data taken from Revolut customers has demanded $3m in Monero within 24 hours.
- It says it picked out customers with significant crypto holdings. That claim comes from the attackers and has not been verified.
- We could not find a primary source. The details reach us through CoinDesk’s write-up, and Revolut’s own account of the demand is not in it.
A group claiming to hold data taken from Revolut customers has put a price on it. Three million dollars in Monero, payable within 24 hours, or the file goes up for sale. That is the demand as reported; Revolut’s response to it is not yet public.
If your identity documents and a record of your account activity are sitting in a file someone is trying to sell, the ransom negotiation is not the part that affects you. The data has already left. What matters is what it can be used for next, which is impersonation: someone contacting your bank, your mobile network or an exchange while holding enough true detail about you to sound like you.
That risk is the same whether the money is paid or not. There is no version of this where a payment pulls the data back.
What is claimed, and by whom

Separating the parts of this matters, because they carry very different weight. The existence of a ransom demand is being reported by CoinDesk. The figure, the deadline and the choice of Monero come from the same write-up. The assertion that the group deliberately singled out customers with large crypto balances comes from the attackers themselves.
Attackers are an interested party. Saying you hold the most valuable slice of a company’s customer base is exactly what you would say to make a deadline bite, and nobody outside the negotiation can currently check it. We are reporting the claim, not adopting it.
Monero is a cryptocurrency built so that outsiders cannot see who sent what to whom. Ransom demands specify it for that reason. A bitcoin payment leaves a public trail that analytics firms follow for years afterwards. A Monero payment mostly does not, which is why it turns up in extortion cases far more often than its size in the wider market would suggest.
How this connects to the earlier incident
This is the second Revolut data story in a fortnight. Earlier this month we covered the firm handing over customer passport images and bitcoin transaction histories in response to a fraudulent law enforcement request, a technique where criminals impersonate a police force or government agency to get a company to hand over records through its normal compliance channel. That story is in our news archive.
Whether the data now being ransomed is the same material has not been established in the coverage we have seen. It would be a reasonable inference given the timing, and we are labelling it as inference rather than fact. Revolut has not confirmed a link, and nor has anyone else.
Why a documented crypto balance changes the risk
Most stolen customer databases give a criminal a name, an address and a way to contact you. A database that also shows roughly how much crypto someone holds gives them a reason to bother.
The follow-on attacks are well documented from previous breaches. SIM swapping, where someone persuades a mobile network to move your number onto their SIM and then uses the text messages to reset your accounts. Impersonation calls, where a person rings claiming to be from the firm’s fraud team, already knowing your recent transactions. Targeted phishing that references real details rather than generic ones, which is the version people fall for.
None of that requires the attacker to have your password. It requires them to sound convincing to a call centre, and a leaked identity document plus a transaction history is a strong script.
What to check, and where to report it
Set up a PIN or port-out protection with your mobile network if you have not already, since the phone number is the weak point in most account recovery. Move any account still relying on SMS codes onto an authenticator app or a hardware key. Treat any inbound call, text or email that claims to be from Revolut as unverified, however much it knows about you, and reach the firm through the app rather than a number someone has given you. The same logic applies to your exchange accounts, and our guide to self-custody covers the trade-offs if you are reconsidering where your coins sit.
In the UK, fraud and attempted fraud go to Action Fraud, or to Police Scotland on 101 if you are in Scotland. If your personal data has been exposed and you are unhappy with how the firm has handled it, that is a matter for the Information Commissioner’s Office. Under UK data protection rules a company has to notify the regulator of a qualifying breach within 72 hours, and has to tell affected individuals directly where the risk to them is high.
What to watch
Whether Revolut contacts affected customers individually rather than issuing a general statement. That is the difference between a company that knows whose data went and one that is still working it out.
Whether the deadline passes and anything actually surfaces. Extortion groups routinely claim to hold more than they do, and the sample that appears after a missed deadline usually tells you which this was. And whether the ICO says anything on the record, because a regulatory response would be the first independent read on the size of this that does not come from either the company or the people threatening it.