The Revolut case at the intersection of traceability and privacy
When personal data turns on-chain wealth into a target
In September 2026, Revolut disclosed a personal data breach affecting approximately 700 customers. According to available reports, the attackers used a certified email account linked to the Prefecture of Reggio Calabria to pose as officers from Italy’s Postal Police. Through a series of requests, they obtained identity documents, contact details and transaction histories. The group iamnotavillain, which claimed responsibility for the operation, subsequently demanded a ransom of $3 million in monero, threatening to sell the information to other criminal organisations.
What initially appeared to be a serious but contained data breach gradually revealed a deeper connection with the crypto-asset sector. According to the attackers, the customers were not selected at random but identified through blockchain analysis based on the holdings associated with them. When the ransom was demanded, however, the group chose monero rather than bitcoin. For those familiar with how crypto-assets operate, the decision is unsurprising: bitcoin’s public and permanent transaction record makes it ill-suited to concealing the movement of funds over time. The Revolut case therefore provides a particularly clear lens through which to distinguish public perceptions of crypto-assets from the actual characteristics of different protocols.
From on-chain analysis to customer identification
According to iamnotavillain’s account to the Financial Times, the approximately 700 customers were selected through on-chain analysis based on the crypto-asset holdings associated with their accounts. The group nevertheless declined to explain its methodology, and the available information does not establish which addresses, transactions or other data were used as a starting point. This distinction is important because a public blockchain makes transfers observable but does not record the identities of the people involved or reveal the balance held in an account with an intermediary. In a custodial service, moreover, addresses may be controlled by the operator and used on behalf of multiple customers, making it impossible to attribute an individual position on the basis of on-chain data alone.
A technically plausible reconstruction can nevertheless outline how the process may have unfolded. Starting with addresses attributed to Revolut’s infrastructure, the attackers could have traced incoming and outgoing flows, identified high-value transactions and examined the external addresses involved. Clustering techniques can then identify groups of addresses that exhibit signs of common control, without revealing the identity of the person behind them. Linking an address to an individual necessarily requires information from outside the blockchain. In this case, the requests submitted to Revolut may have served precisely this purpose, allowing a particular address or transaction to be matched with data held in the intermediary’s systems. Revolut states that, when applying the Travel Rule, it retains information about the originator and beneficiary together with the transaction identifier. Through repeated requests, the attackers may therefore have converted an initial selection based on public flows into profiles containing identities, contact details, documents and transaction histories.
The criminal value of the stolen data
The value of the dataset does not depend on the presence of login credentials, private keys or other information that would allow the crypto-assets to be transferred directly. Revolut has stated that neither its systems nor customer funds were compromised. The risk instead arises from the combination of identities, contact details, documents and transaction histories, which can be used to build highly detailed personal and financial profiles. By referring to genuine transactions, an attacker could impersonate Revolut or another intermediary, claim that an account has been compromised and induce the victim to transfer crypto-assets to a purportedly secure wallet, visit a fraudulent website or disclose authentication codes and recovery phrases.
The combination of a telephone number and identity data may also facilitate SIM swapping, whereby a criminal transfers the victim’s number to a SIM card under their control in order to intercept codes sent by text message and attempt to reset access to email accounts, crypto-asset trading platforms and other financial services. Copies of identity documents may also be used in attempts to open accounts with other providers and use them to receive or transfer illicit funds. The most serious risk, however, arises when a home address is linked to presumed crypto-asset holdings, enabling criminals to select victims for extortion, home invasions or kidnappings intended to force a transfer. Chainalysis has identified the circulation of datasets containing names, addresses and crypto-asset holdings as one possible factor behind the increase in physical attacks recorded in France, illustrating how a data breach can create a threat to personal safety long after the original incident.
The ransom demand and the choice of monero
Possession of such sensitive information gave the group the leverage to attempt to extort Revolut. On 16 September, iamnotavillain published a demand for 6,000 XMR, approximately $3 million, giving the bank 24 hours to pay before putting the documents up for sale. The following day, Revolut stated that it had received no direct communication from the group. The publication of the ultimatum is therefore documented, but there is no evidence that negotiations began or that the ransom was paid.
The choice of monero is consistent with this extortion strategy. Privacy is not an optional feature but a property built into the protocol and enabled by default. Stealth addresses generate a different destination for each payment, ring signatures make it harder for an outside observer to identify the actual sender, and Ring Confidential Transactions conceal the amount transferred. The network can therefore verify the validity of a transaction without making its essential details publicly visible. This architecture makes monero particularly suited to situations in which the objective is to limit the reconstruction of financial flows through blockchain analysis.
The same characteristics are, however, driving its gradual exclusion from regulated markets. From 10 July 2027, Regulation (EU) 2024/1624 will prohibit credit institutions, financial institutions and crypto-asset service providers from maintaining accounts that allow the identity of the holder to be anonymised or transactions to be further obfuscated, including through anonymity-enhancing coins. The new framework will therefore sharply restrict the availability of monero trading and custody services from regulated intermediaries in the European Union. The provision does not impose a general ban on holding or using the protocol, but it will substantially reduce access through Europe’s regulated financial infrastructure.
The gap between perception and evidence
A ransom demand in monero may appear counterintuitive to those viewing the sector from the outside. In the public imagination, crypto-asset extortion is still associated almost automatically with bitcoin, a perception formed during its early adoption, when its use in illicit online marketplaces helped shape its public image. This legacy has encouraged the belief that bitcoin provides anonymity and is therefore the most effective instrument for concealing illicit proceeds. The protocol operates differently: transactions are pseudonymous, but they remain public and permanently recorded. Once an address is linked to an individual or a service, its transaction history can be reconstructed even years later. For anyone seeking to conceal the movement of funds over time, this persistence represents a structural constraint.
The composition of illicit flows also challenges the automatic association between bitcoin and criminal activity. According to Chainalysis’s 2026 Crypto Crime Report, addresses associated with illicit activity received at least $154 billion in 2025, a figure driven largely by flows involving sanctioned entities. Stablecoins accounted for 84% of the illicit volume identified, while illicit activity represented less than 1% of the total volume attributed by the company. These estimates are revised as new illicit addresses are identified and do not capture every form of criminal activity. They nevertheless show that illicit flows are not concentrated in bitcoin and that the choice of instrument depends on the requirements of each operation.
Security beyond custody
For intermediaries, the Revolut case shows that the security of crypto-asset services cannot be confined to protecting private keys and custody infrastructure. When held directly, crypto-assets can resemble digital bearer instruments: anyone who gains control of the private keys, or induces the holder to authorise a transfer, can move the value without an ordinary mechanism for recalling the transaction. Identity documents, contact details, holdings and transaction histories can therefore become a map of potential targets, particularly when combined with information observable on the blockchain. Controls must consequently extend to verifying requests from public authorities, segregating access rights, minimising the data disclosed and detecting repeated or anomalous requests. The available information does not indicate that Revolut’s custody systems were compromised. The risk that emerged instead concerns the operational processes through which external parties may gain access to customer data.
For holders of substantial crypto-asset wealth, the choice of intermediary should therefore depend not only on financial soundness, the range of services offered and the measures used to safeguard assets, but also on the ability to protect information revealing the existence and scale of those holdings. The fact that the incident involved an organisation as established as Revolut does not demonstrate that the intermediary was unprepared. It instead shows that residual risk remains even within mature organisations and may be concentrated in operational processes rather than technological infrastructure.
Conclusions
The Revolut case shows that crypto-asset security extends beyond custody. Information linking an identity to financial holdings and transactions can itself become an instrument of attack. The most significant feature of the case lies in the asymmetry between on-chain transparency, which was allegedly used to select potential targets, and the privacy sought through monero to receive the ransom. This dynamic also exposes the limits of the association between bitcoin and criminal activity, as different protocols offer markedly different levels of traceability. Intermediaries must therefore extend protection to the processes governing access to and disclosure of customer data, while customers should consider the ability to safeguard this information when selecting a provider. Without implying any broader judgement about Revolut’s reliability, the incident demonstrates that data protection is an integral component of financial security.