Gang claiming responsibility for Revolut data breach demands 6,000 Monero coins, about $3 million, within 24 hours
The Financial Times reports that a gang claiming responsibility for the Revolut data breach has publicly demanded the payment of 6,000 Monero coins, approximately $3 million, within 24 hours, threatening to sell customer data to other criminal groups if the payment is refused, with a countdown timer displayed on their page.
A Revolut spokesperson stated that the company has not received direct contact or ransom demands from the gang, nor has there been any negotiation. Sources indicate that the core systems and customer accounts have not been breached, affecting about 680 individuals. The company previously explained that sensitive information was disclosed to unauthorized third parties due to fraudulent requests from legitimate government email domains.
Italian prosecutors have launched an investigation into the use of a government-certified email to impersonate law enforcement in order to obtain specific customer data. The gang told the media that their targets are primarily users with large on-chain balances, mostly from Switzerland and France, with others scattered across more than thirty countries. The materials notifying customers include names, birth dates, addresses, identification documents, and some transaction records.
Public extortion is not common in such cases, as offers are usually made privately. Monero has been singled out as a payment asset due to its difficulty in being traced. The countdown is a pressure tactic and does not constitute a confirmed transaction.
In market mechanisms, this is a reputational and compliance event, not an exchange run. The beneficiaries are security firms providing regulatory-level data retrieval verification and privacy computing; the pressured party is Revolut's narrative regarding its European license and retention of high-net-worth crypto clients. Funds will not shift to stablecoins or Monero pricing due to a sample of 680 individuals; the mention of Monero only increases short-term attention without changing its liquidity structure.
Source: Public information
ABAB AI Insight
The gap is not in the core ledger, but in the manual process that "looks like a government letter." The 680 individuals are not the total user base but a targeted high-balance sample, indicating that the attackers had prior on-chain filtering followed by a document channel. The company denies receiving a direct ransom, and the gang's countdown displayed on their website creates a public spectacle: whether to pay or not is being observed under a public clock.
The capital path is that fintech automates compliance retrieval; once a forged source passes verification, data can exit through legitimate processes. The demand for Monero shifts the tracing from the ledgers familiar to Bitcoin analysts to privacy coins. The investigation into the Italian email expands the incident from a UK licensed entity to a cross-border public service issue.
This is analogous to phishing targeting crypto executives after 2022, and traditional bank "fake police calls": a new layer involves the actual theft of government domains. The industry is at a stage where identity verification is strong, but source verification is weak.
Structural judgments belong to operational risks triggered by regulatory changes. The mechanism is that licensed institutions must respond to law enforcement requests; if the retrieval channel is misused, the obligations of confidentiality and assistance collide. Whoever can make document verification an unforgeable channel will have one less gap in the next round of license reviews.
ABAB News · Cognitive Laws
- When the core ledger is intact, document processes can still send data out.
- Public countdowns sell the pressure of observation, not confirmed ransom.
- Those first named on-chain are often also on the retrieval list.