TL;DR
- A group calling itself IAmNotAVillain has issued a $3 million Revolut ransom demand payable in 6,000 XMR.
- The group threatens to sell stolen customer data, while Revolut says none of the competing claimants has contacted it directly.
- Around 680 customers were targeted after fraudulent requests from a legitimate government-agency email domain led Revolut to disclose sensitive data.
A group calling itself “IAmNotAVillain” is demanding $3 million ransom from Revolut, payable in Monero. It says it will sell stolen customer data if the company does not pay. The threat adds extortion to a breach that started with a forged government request.
What happened
Revolut disclosed last week that fraudulent requests from a legitimate government-agency email domain led it to hand sensitive customer data to an unauthorized party. The company confirmed the breach on September 12.
>>> Read more: Revolut Data Breach: Stolen Files Appear Online
The ransom demand
IAmNotAVillain published the ransom demand to Revolut on its website Wednesday afternoon, alongside a running countdown clock. The message set a 24-hour deadline for 6,000 XMR, roughly $3 million, or the data would be sold.
The group chose Monero over Bitcoin deliberately. Monero transactions are harder to trace than Bitcoin, the currency an earlier, competing claimant had demanded.
The group sent the Financial Times a one-minute recording of someone scrolling through what it called Revolut customer files.
Which government agency?
Revolut never named the government agency whose domain the fraudulent requests used. Italian reporting has since filled that gap independently: multiple outlets identified the account as belonging to the Prefecture of Reggio Calabria, tied to Italy’s Interior Ministry.
Prosecutors in Reggio Calabria opened an investigation into unauthorized access to a government computer system. Italy’s National Anti-Mafia and Anti-Terrorism Directorate joined the probe, since the case involves a government entity. Investigators are trying to determine whether someone breached the institutional email account or cloned it. Revolut has continued to decline naming the agency, citing the active investigation.
IAmNotAVillain separately claimed to hold 147 GB of material pulled from Italian law-enforcement systems, gathered over a six-month operation. The cache reportedly includes internal documents and personal files such as calendars. Italian authorities have not confirmed a breach of police systems. The claim describes a target far larger than the Revolut customer data itself.
How the group chose its targets
The group told the Financial Times it identified its roughly 680 targets through on-chain analysis, cross-referencing blockchain activity with Revolut accounts to find customers holding substantial crypto balances. It called them “crypto whales.”
Switzerland and France account for most of the affected accounts. The remainder spread across 31 other countries. National figures reported separately put the count at 12 in Ireland, 25 in Spain, and 27 in Romania.
The method gives an attacker-side account to an earlier claim from security researcher ZachXBT. He said the operation looked aimed at high-net-worth users, not a mass dump of Revolut’s customer base.
Whoever is behind this
Multiple identities have claimed responsibility for the breach, and they contradict each other. A group calling itself “Revolut Smilik” previously demanded 10,000 Bitcoin, worth roughly $780 million at the time. IAmNotAVillain publicly disputed the claim, alleging a former associate leaked a small sample before claiming credit for the breach. The group warned others not to deal with the rival.
A third site, revoloot.lol, surfaced separately with its own claim of responsibility, according to Dark Web Informer. IAmNotAVillain’s own site went offline around the time Cointelegraph checked it for comment.
Revolut maintains none of the claimants has made direct contact, a position the company has repeated with each new demand.
>>> Read more: Violent Crypto Attacks Surge: $30M Stolen in Half-Year
Regulatory fallout
Britain’s Information Commissioner’s Office confirmed it received a report on the incident and is assessing the information provided. The Financial Conduct Authority is engaging with Revolut separately.
Italy’s data protection authority ordered banks nationwide to review their data-access systems and report any vulnerabilities. The regulator also contacted its Lithuanian counterpart, since Revolut’s registered office sits in Lithuania.








