Trusted independent reportCross-border relevantPublication date verified
CoinDesk
INVOLVES · Revolut
Revolut hackers demand $3 million in Monero, threaten to sell customer data
WHAT HAPPENED
CoinDesk reports that attackers demanded $3 million, or 6,000 XMR, after claiming to have obtained customer data tied to at least 680 Revolut accounts. The reported material includes identity documents, know-your-customer records and transaction histories, and the article says fraudulent government-information requests passed verification checks. Revolut said its systems and customer funds were unaffected, blocked the payment address, notified authorities and would not negotiate; it had not commented publicly by publication time.
PUBLISHED September 16, 2026SOURCE CoinDeskLANE Cross-border market
KEY FIGURES
$3 million or 6,000 XMR
Ransom demanded
at least 680
Accounts reportedly involved
WHAT TO WATCH NEXT
Watch whether Revolut disclose verified recovery or return amounts, the confirmed root cause, remediation, reopening timing, and customer impact.
Readable CoinDesk report drawing on Financial Times reporting. The ransom demand and alleged dataset are attacker claims; Revolut says its systems and customer funds were unaffected. No independent forensic report, confirmed payment interruption or final loss figure is available.
The page already presents the summary and analysis. This section keeps only the copy, download, and technical source record without repeating the same reading view.
View technical text
# Revolut hackers demand $3 million in Monero, threaten to sell customer data
> Evidence tier: B1
> Evidence type: Independent report of an alleged customer-data breach and cryptocurrency ransom demand
> Source: [CoinDesk](https://www.coindesk.com/markets/2026/09/16/revolut-hackers-demand-usd3-million-in-monero-threaten-to-sell-customer-data)
> Published: 2026-09-16
> Captured: 2026-09-17T01:38:53.227Z
## Source summary
CoinDesk reports that attackers demanded $3 million, or 6,000 XMR, after claiming to have obtained customer data tied to at least 680 Revolut accounts. The reported material includes identity documents, know-your-customer records and transaction histories, and the article says fraudulent government-information requests passed verification checks. Revolut said its systems and customer funds were unaffected, blocked the payment address, notified authorities and would not negotiate; it had not commented publicly by publication time.
## Why it matters
The incident matters to a cross-border provider because exposure of identity and transaction records can raise fraud, privacy and compliance risks even when payment systems and balances remain intact. The attackers' access and dataset claims are allegations reported through the Financial Times and CoinDesk, not independently verified facts. No payment outage, customer-fund loss, settlement impact or final regulatory outcome has been established.
## Key numbers
- **Ransom demanded:** $3 million or 6,000 XMR
- **Accounts reportedly involved:** at least 680
## Topics and entities
- Industry lane: Cross-border market
- Entities: Revolut
- Cross-border payments
- Payment infrastructure
- Company intelligence
## Evidence and credibility note
Readable CoinDesk report drawing on Financial Times reporting. The ransom demand and alleged dataset are attacker claims; Revolut says its systems and customer funds were unaffected. No independent forensic report, confirmed payment interruption or final loss figure is available.
Date evidence: CoinDesk JSON-LD records 2026-09-16T19:07:34.064Z and the readable article is dated September 16, 2026
## First-party corroboration
No directly corresponding A1 company announcement is currently linked.
## Original-source traceback
[Open the original CoinDesk report](https://www.coindesk.com/markets/2026/09/16/revolut-hackers-demand-usd3-million-in-monero-threaten-to-sell-customer-data)
---
This is a structured Payments Hot Markdown source summary derived from external reporting. Use the original link above to read the publisher's article; copyright remains with the original publisher.