A group calling itself iamnotavillain says it wants 6,000 XMR, or roughly $3 million, in exchange for not selling data it claims to have obtained from Revolut customers. The demand, described in messages to the Financial Times, replaced an earlier bitcoin figure that the group later said had been posted by an impersonator or former associate.
The alleged incident does not appear to involve a break-in to Revolut’s core systems. Instead, the attackers claim the company sent customer information in response to fake law-enforcement requests that appeared to come through Italy’s certified government email system.
What the attackers say they obtained
According to the group’s account to the Financial Times, the operation yielded files on about 680 people across 31 countries, with many of the affected users in Switzerland and France. The attackers said they selected targets based on onchain analysis that suggested substantial cryptocurrency activity.
The records allegedly include names, addresses, phone numbers, account IDs, fiat transfer details, crypto deposits and withdrawals, and know-your-customer material such as passports and verification selfies. If accurate, the cache would amount to detailed identity and transaction profiles rather than basic contact data.
How the alleged scheme worked
The attackers claim they spent months posing as Italian law enforcement and submitting requests for specific users’ records. They allegedly relied on Italy’s Posta Elettronica Certificata, or PEC, a certified email network used for official and legal communications.
Because messages sent through that channel carried valid domain authentication, the requests appeared to come from a legitimate government authority. The weakness, as described in the reporting, was not email authentication itself but the inability to confirm that the person behind the account was an authorized official.
Public ultimatum and payment switch
On Sept. 16, iamnotavillain posted a countdown on a website bearing the same name and threatened to sell the files to other criminal groups within 24 hours unless it was paid 6,000 XMR. The use of monero would make any payment harder to trace than a bitcoin transfer.
An earlier demand for 10,000 bitcoin had circulated on Telegram, but the group later distanced itself from that number, saying it came from an impersonator or former associate. Revolut, for its part, said it had not received a direct demand from the people claiming responsibility when the countdown went live.
Revolut’s response and what remains under review
Revolut has said customer funds and its systems were not affected, indicating that the attackers did not penetrate the company’s core network or drain accounts. The company’s stated position is that the issue centered on fraudulent requests for information, not a compromise of internal infrastructure.
The company also said it identified the impersonation scam, blocked the address involved, and notified the relevant agency, law enforcement, and regulators. The next confirmed step is the continuing investigation into how a legitimate government communications channel was used in the operation and whether similar requests may have been sent to other crypto-related institutions.
Source: news.bitcoin.com