Revolut Denies Direct Contact Following $3 Million Public Ransom Demand

Revolut announced that it has not received any direct communications from parties demanding ransom for customer data despite public ultimatums. The group calling itself “IAmNotAVillain” publicly demanded 6,000 Monero (approximately $3 million) threatening to sell customer records to other criminal gangs. Meanwhile, Italian authorities have expanded their investigation following a data breach involving a government email account.
No Direct Contact Despite Public Ransom Demands
Revolut confirmed it has not engaged in any direct communications with individuals or groups claiming responsibility for the breach and demanding ransom. On Wednesday, Financial Times reported that "IAmNotAVillain" publicly issued an ultimatum demanding 6,000 Monero (around $3 million) within 24 hours, threatening to sell customer data to other criminal entities.
A Revolut spokesperson told Cointelegraph the company has yet to receive any direct, official demand or communication, casting doubt on who is actually behind the public ransom claims.
Multiple Claimants to the Breach Responsibility
"IAmNotAVillain" is not the only entity asserting involvement. An earlier group known as "Revolut Smilik" reportedly demanded 10,000 Bitcoin — about $780 million at the time — far exceeding the $3 million Monero demand from "IAmNotAVillain".
On its website, "IAmNotAVillain" disputed these competing claims, alleging that the rival group had only obtained a small sample of the data and wrongfully claimed credit for the breach. They also warned others against transacting with this rival.
Furthermore, cybersecurity sources point to a third actor linked with the domain revoloot.lol, adding further complexity. The websites for these groups were inaccessible at the time of verification by Cointelegraph, hindering confirmation.
Italian Authorities Broaden Investigation
Italy’s National Anti-Mafia and Anti-Terrorism Directorate has started investigating due to the suspected involvement of a government email account. According to ANSA, prosecutors in Reggio Calabria opened a case into unauthorized access of a public-interest computer system.
Investigators are working to determine whether the institutional email was hacked or cloned.
Separately, Italy’s data protection regulator has urged banks to urgently assess their access security protocols and is examining whether other banks or financial institutions may also have been compromised.
Why it matters
This news highlights the complexity and ambiguity surrounding the investigation of a major data breach in the financial sector. The lack of direct contact with the ransom claimants and multiple groups asserting responsibility complicate the situation and hinder prompt response. Beyond reputational risks for Revolut, involvement of Italian authorities and the use of a government email account underscore systemic vulnerabilities and data security risks within banking. The actions taken by Italian regulators signify a robust approach to protecting customers and may lead to broader scrutiny across the sector.
Prepared from the source material with AI-assisted editing and checked against the supplied facts.
Open original source ↗