Revolut hackers demand $3mn ransom
A hacking group calling itself iamnotavillain is demanding $3mn from Revolut, threatening to sell customers’ confidential data unless the UK fintech pays within 24 hours. The short deadline creates immediate pressure around customer protection, regulatory scrutiny and confidence in Revolut’s platform.
The Financial Times reported that a group using the name iamnotavillain has threatened to sell confidential Revolut customer data to other criminals unless the UK fintech pays a $3mn ransom within 24 hours. The report does not establish how many customers are affected, what information was allegedly obtained or whether Revolut has verified the hackers’ claims.
The immediate issue is the combination of a claimed data breach and a compressed response window. The 24-hour demand leaves little time for independent verification, containment and decisions over customer notification or engagement with law enforcement.
For Revolut, the potential mechanisms are direct and concrete: a verified exposure could bring remediation costs, regulatory attention and customer-support demands, while a false or unsubstantiated claim would still require investigation and public communication. The threatened sale of data to other criminals raises the possibility of secondary fraud or account-takeover attempts if the claims prove credible.
The Financial Times did not say whether Revolut had confirmed a breach, agreed to pay, contacted authorities or identified the affected data. Those unresolved points are central to assessing the operational and financial impact.
The next decisive developments are Revolut’s response within the stated 24-hour window, any confirmation from law enforcement or regulators, and evidence establishing whether customer data was accessed. The number of affected accounts, the type of information involved and any required customer remediation would determine the scale of the fallout.
The alleged breach puts Revolut’s customer trust and regulatory exposure in focus, but no listed-company trade is established without confirmation of the claim or its impact.
The immediate consequence is uncertainty rather than a quantified financial hit: the ransom demand could become a material trust, remediation and regulatory problem if the data claim is verified, but the Financial Times report does not establish that a breach occurred. The decisive evidence is Revolut’s response, independent confirmation of the alleged access and disclosure of how many customers and what data were affected.
The trade case fails if Revolut or authorities establish that the claim is false, immaterial or unrelated to customer data.
CoverageSource: Financial Times · Published here WED, SEP 16 · 1:58 PM ET · 2 reports · 2 publishers in this record · latest listed: CoinDesk · WED, SEP 16 · 3:08 PM ETHow this is decided →
Earlier context and later coverage are dated relative to this report. Automatically linked reports may cover a broader event.
No later reports linked yet.
Follow this story to find new evidence in your Following desk.
Revolut could contain the incident without paying if the alleged breach is unverified and no customer data is shown to have been accessed.
A confirmed exposure of confidential customer data could trigger customer remediation, regulatory scrutiny and secondary fraud risk, but the report gives no quantified scope.
Kept as written · your side, if you take one, is graded privately against licensed closes after 10 trading days · nothing here is advice · How the Wire is made →