The group says it targeted Revolut customers holding large crypto balances and wants payment in the privacy coin Monero. A group claiming to have breached digital banking platform Revolut say
The group says it targeted Revolut customers holding large crypto balances and wants payment in the privacy coin Monero.
A group claiming to have breached digital banking platform Revolut says it is demanding 6,000 Monero from the company, according to a report published by Unchained. The group reportedly stated that it specifically sought out customers who held large amounts of cryptocurrency through their Revolut accounts.
Monero, often abbreviated XMR, is a privacy-focused cryptocurrency designed to obscure transaction details, including sender, receiver, and amount. Its use in ransom demands is not new. Groups behind extortion attempts frequently prefer Monero over Bitcoin because its ledger does not expose wallet balances or transaction histories to public blockchain analysis in the same way.
The claim, as reported, has not been independently verified by Revolut or by outside security researchers at the time of this report. Revolut has not issued a public statement confirming a breach of its systems or acknowledging the ransom demand described by the group.
Revolut operates as a financial technology company offering banking, currency exchange, and cryptocurrency trading services to millions of customers globally. Its crypto offering allows users to buy, hold, and in some cases transfer digital assets directly from the app. A confirmed breach targeting crypto holders specifically would raise questions about how customer account data, including balance information, may have been accessed or exposed.
Claims of this nature are common in the wake of alleged cyberattacks, and not all such claims are later substantiated. Extortion groups sometimes exaggerate the scope of data obtained, or make demands designed to generate media attention rather than reflect a fully executed breach. Until Revolut or independent investigators confirm details, the extent of any actual compromise, and whether customer funds or personal data were genuinely accessed, remains unclear.
The reported targeting of crypto holders specifically is notable given the broader pattern of attacks against exchanges, wallets, and fintech platforms that offer digital asset services. Financial platforms that combine traditional banking with crypto access present an attractive target for attackers because a single account can expose both fiat balances and digital asset holdings. Security researchers have long warned that platforms bridging traditional finance and crypto carry unique risks, since a breach can potentially expose users across both asset classes simultaneously.
If the claims prove accurate, the incident would add to a growing list of cyberattacks against companies that serve as gateways between conventional banking and digital assets. Regulators and security professionals have repeatedly flagged this intersection as a point of vulnerability, given the difficulty of applying uniform security standards across both traditional and crypto-native infrastructure.
Market Impact
Should the breach and ransom demand be confirmed, Revolut could face reputational and regulatory scrutiny over how it protects customer data and crypto holdings. Fintech platforms offering both banking and crypto services may see renewed pressure to demonstrate stronger security practices following any confirmed incident of this kind.
A demand denominated in Monero also draws attention to the privacy coin's continued use in extortion cases, a factor that has previously influenced exchange delisting decisions and regulatory discussions around privacy-preserving cryptocurrencies. Until the claims are verified, however, direct market effects on Revolut's operations or on Monero's trading activity remain speculative.
The claims remain unverified by Revolut or independent investigators, and the full scope of any actual breach is not yet clear. Readers should treat the ransom demand and targeting claims as reported allegations pending further confirmation.
Frequently Asked Questions
Has Revolut confirmed the breach or ransom demand?
No. As of this report, Revolut has not publicly confirmed a breach or acknowledged the demand for 6,000 Monero described by the group.
Why would attackers demand Monero instead of Bitcoin?
Monero uses privacy features that obscure transaction amounts and wallet addresses, making it harder to trace than Bitcoin, which is often cited as a reason extortion groups prefer it.
What does it mean that the group says it 'hunted' large crypto holders?
According to the report, the group claims it specifically identified and targeted Revolut customers who held significant cryptocurrency balances, rather than attacking accounts at random.
Is there evidence customer funds were actually stolen?
The report describes a ransom demand and targeting claim from the group, but does not confirm whether any customer funds or data were actually accessed or stolen.
Update 17 Sep 2026, 00:55 UTC · added by Bitcoin.com News
Bitcoin.com News reports the attackers initially demanded payment in bitcoin before switching to the 6,000 XMR (about $3 million) demand, and specifies the ransom covers 680 customer files. The outlet also details the alleged method behind the breach: criminals reportedly posed as officials using a real Italian email system to obtain the records from Revolut.
Originally reported by AltcoinGordon, written by Noah Sullivan. Republished with permission.
View the original on AltcoinGordon →
The post Hacking Group Claims Revolut Breach, Demands 6,000 Monero From Crypto-Rich Users appeared first on TheCoinrise.com.