Blockchain investigator ZachXBT, who first sounded the alarm on the Revolut extortion incident, stated that the attack appeared intentionally targeted at high-profile crypto users. A report from Decrypt confirmed the suspicion, detailing how the hacking group selected the 680 victimized customer accounts.
The hackers ran blockchain analysis beforehand to identify Revolut customers with substantial on-chain crypto holdings before targeting their accounts. This marks the first publicly documented case where on-chain analysis was actively used to pick extortion targets - rather than merely serving to trace fund flows after theft.
However, this ability to read crypto wallets was paired with deception tactics targeting customer support procedures directly.
Compromised Italian Government Email
The attackers obtained customer data through an Italian government email system they had compromised for several months.
Revolut complied and handed over the data because the incoming information requests originated from a legitimate government agency email domain with valid authentication. This manipulation tactic falls under sophisticated external impersonation fraud.
The stolen information includes personal identities such as names, dates of birth, occupations, residential addresses, copies of passports or driver’s licenses, and KYC verification selfies. The perpetrators also secured account statements containing IBAN numbers, wallet references, withdrawal records, and full transaction histories belonging to customers.
Why Demand a Monero Ransom
Through a dedicated website, the hacking group posted their ransom demand of “6,000 XMR / $3,000,000” alongside threats to sell all stolen data if the ransom is not paid.
The choice of Monero stems from its ring signature and stealth address features, which obscure the identities of senders, receivers, and transaction amounts. This high level of privacy is also why major crypto exchanges like Binance, Coinbase, and Kraken delisted Monero from their platforms.
The Monero ransom demand slightly deviates from broader cybersecurity trends. Blockchain intelligence firm TRM Labs noted that most cyberattacks today are still settled in Bitcoin, as the asset is far easier to acquire, transfer, and liquidate at scale.
The Revolut breach serves as a stark reminder for crypto investors: the transparency of public ledgers is now being turned against users to undermine privacy on centralized platforms.
Reported by Decrypt.
Previously: Revolut Held for 6,000 Monero in 24 Hours - 680 Customers’ Passport Data at Stake
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




