A criminal group calling itself iamnotavillain has given Revolut a 24-hour deadline: pay 6,000 XMR, roughly $3 million, or see stolen customer documents published. The company said it has received no direct contact from the extortionists.
A 24-Hour Deadline and Rival Claimants
The demand appeared Wednesday on a separate website, iamnotavillain.xyz, that the group built for the purpose. The site asks for exactly "6,000 XMR / $3,000,000" and warns that hundreds of customers' data will be sold to other criminals once the deadline passes.
"All the data will be sold, and the blood will be on your hands."
- from the demand posted by iamnotavillain, cited in a Financial Times investigation
Only one group is not claiming credit here. An earlier actor calling itself "Revolut Smilik" had reportedly demanded 10,000 Bitcoin, worth about $780 million at the time, or hundreds of times more than the current Monero ask. iamnotavillain publicly disputed that claim, alleging the rival was a former associate who received only a small sample of the data before taking credit for the whole breach. A third thread came from researchers at Dark Web Informer, who spotted another site, revoloot.lol, tied to yet another actor claiming responsibility.
Revolut, a UK-based neobank, lets users buy, hold and trade crypto directly inside the app. That is why the company had accumulated records linking a customer's identity to specific wallets and the value held in them, and those records are exactly what the attackers went after.
How the Attackers Picked Their Targets
What sets this breach apart is the selection method. Rather than blasting the demand at everyone in a stolen database, iamnotavillain told the FT it ran blockchain analysis first. Public transaction history combined with verification data can reveal how wealthy a wallet owner is without ever touching a password or a private key. Blockchains are transparent by design, and anyone can see the balance and flow of funds at an address. The main barrier for an attacker is simply tying that address to a real person.
After picking out Revolut customers whose on-chain activity suggested substantial holdings, the hackers went after those specific accounts. That approach sets the breach apart from a typical data dump, where criminals just release an entire database with no filtering by victims' wealth. Monero was not a random choice either, since the privacy coin hides sender, recipient and amount using ring signatures, which makes a payout almost impossible to trace.
The Breach Came Through a Fake Government Request
Revolut handed the data over itself, responding to requests that arrived from a genuine government email domain with valid authentication. The company called it "a sophisticated external impersonation scam." According to the FT, the requests came through a compromised Italian government email system over a period of months, not in a single incident.
The scale of what was taken is striking:
- names, dates of birth, occupations and home addresses of customers
- copies of passports and driving licences along with verification selfies
- account statements with IBANs and wallet addresses
- withdrawal history and full transaction records
Italy's National Anti-Mafia and Anti-Terrorism Directorate has widened its probe because the intrusion involves a government entity. Prosecutors in Reggio Calabria opened a case over unauthorized access to a computer system and are trying to establish whether the email account was hacked or cloned. Italy's privacy regulator has separately asked banks to urgently review the security of their own access systems, while also checking whether other financial institutions were involved. Because Italy is an EU member, a leak of personal data on this scale falls under GDPR, opening the door to a separate investigation and fines for whichever party failed to secure the data channel.
The episode revived an old question in fintech: how safely neobanks store passport scans, verification selfies and full financial histories in a single place.
Revolut's Response and the Risk for Crypto Holders
Revolut said Wednesday evening it "has not received any direct contact or demand from the individuals or group making these claims." The company calls the number of affected customers "limited," says funds and systems were untouched, and declined to name the agency involved.
Blockchain investigator ZachXBT, who first circulated the customer notification, described the breach as targeted at high net worth users, which matches the attackers' own account of their selection method. The combination of a verified identity, a home address and proven crypto holdings forms the exact profile behind the recent rise in so-called wrench attacks, where crypto owners are physically coerced into handing over wallet access.
Major exchanges, including Binance, Coinbase and Kraken, have already delisted Monero over its anonymity, even as most ransoms are still requested in Bitcoin for its ease of quick transfer. For Revolut customers, all of this means even an indirect link between a wallet and an account can turn crypto holdings into a target for extortion, not just a theft.




Comments
Your email address will not be published. Required fields are marked *