Revolut said it has received no direct ransom demands following a recent data breach. Certik analyst Jonathan Riss warned that mandatory know your customer (KYC) rules force platforms to store sensitive identity data, making them high-value targets for hackers.
Revolut Denies Hacker Contact Over Reported $3M Ransom Claim

Key Takeaways
- Revolut said it received no direct ransom demands after hackers stole data from 680 European clients.
- Certik analyst Jonathan Riss warned that strict KYC mandates create high-value targets for cybercriminals.
- Regulators and fintech platforms like Revolut may need to reduce identity data retention to curb security risks.
No Direct Demands Received, Revolut Says
Revolut said it has not received direct contact from or demands by any group claiming responsibility for a recent data breach. The fintech company’s denial came less than 24 hours after reports that hackers demanded 6,000 XMR, valued at $3 million, to keep the illegally accessed customer files off the market.
The London-based fintech firm confirmed earlier this month that an unauthorized third party obtained sensitive information belonging to a limited number of customers by using a legitimate government agency’s email domain to submit fraudulent data requests. Public statements posted online this week by a hacker operating under the name “IAmNotAVillain” threatened to release or sell customer data unless Revolut paid.
“Revolut has not received any direct contact from or demand by the individuals or group making these claims,” a company spokesperson is quoted as saying. The breach, which reportedly targeted about 680 high-net-worth customers across Europe, did not involve a direct technical intrusion into Revolut’s core systems.
Instead, the attackers used social engineering to impersonate government authorities over several months, obtaining customer verification files, identity documents and transaction records. Revolut emphasized that customer funds and internal systems remain secure and unaffected. The company said it blocked the fraudulent email address upon discovering the breach and reported the incident to law enforcement, data protection authorities and financial regulators.
Analyst warns of KYC vulnerabilities
The incident highlights broader systemic vulnerabilities in how financial institutions handle mandatory identity data. Jonathan Riss, an open-source and blockchain intelligence analyst at security firm Certik, argued that the root cause extends beyond individual companies’ defenses to regulatory requirements themselves.
“The real issue is that KYC has created an extremely sensitive identity layer that financial platforms are required to maintain, often because governments and regulators demand increasingly detailed customer information,” Riss said. “Responsibility, therefore, does not sit only with banks, fintechs or cryptocurrency exchanges.”
According to Riss, public authorities also need to consider whether every piece of information they require is genuinely necessary and how long it should be retained. They should inquire whether existing procedures for requesting customer data are sufficiently secure.
Riss, meanwhile, noted that the exposure of detailed identity files can carry heightened real-world risks in the digital asset sector. “Platforms should still minimize retention, restrict access and strengthen the authentication of government and law enforcement requests through independent verification channels,” Riss added.
While the debate over the hackers’ tactics will continue, Riss believes the incident should prompt the industry and regulators to rethink the current model. The objective should no longer be limited to protecting wallets and funds; it should also include protecting users’ financial identities.

















