The hacker group calling itself “iamnotavillain” has publicly demanded a $3 million ransom in the privacy coin Monero from Revolut, threatening to sell stolen customer data within 24 hours if the London-based fintech does not pay, according to Euronews . The group posted the demand on a dark-web site on Wednesday, September 16, days after Revolut confirmed a breach that exposed identity documents belonging to roughly 680 European customers.
How Attackers Reached Revolut’s Data
Attackers obtained the records using a compromised institutional email account belonging to the Reggio Calabria prefecture in Italy, letting them submit requests that appeared to come from a government body, Italian prosecutors said. Revolut confirmed the incident last week and said customer funds were not touched, though identity documents, birth dates and contact details were exposed. The company had earlier detailed the fake government request that compromised customer information, describing a sophisticated external impersonation scam. Investigators are still working to establish whether the institutional email account from which the requests originated was infiltrated or cloned, a measure of how carefully the operation was prepared.
A Public $3 Million Monero Demand
The group, which the Financial Times said it contacted via Telegram, asked Revolut to transfer “6,000 XMR / 3,000,000 $” or, in its words, “all the data will be sold and you will have blood on your hands.” XMR is the ticker for Monero, a privacy coin often used in illicit contexts because transactions are difficult to trace. The hackers claim to hold 147 gigabytes of data spanning passports, driving licences, identity documents and photographs, and threatened to sell the material to other criminal organisations if payment does not arrive within 24 hours. The Financial Times observed that publishing a ransom demand is unusual, since extortion attempts are normally made privately at first and only aired when a target refuses to negotiate.
Prosecutors and Regulators Respond
Italy’s National Anti-Mafia and Counter-Terrorism Directorate is working on the case, and prosecutors in Reggio Calabria are weighing an offence of intrusion into an IT system of public interest, Euronews reported. Investigators said the operation appeared to have lasted months and are still determining whether a computer at the prefecture or at Italy’s Interior Ministry was compromised. The Italian data protection authority has opened checks and contacted its counterpart in Lithuania, where Revolut’s registered office is located. The incident is the latest in a string of attacks that abuse government data requests to reach private customer records, alongside breaches such as a recent Trezor customer data exposure .


