Chaos Erupts Around Revolut Data Breach as Competing Ransom Demands Mount
Multiple criminal actors claim responsibility for a major Revolut customer data breach with conflicting ransom demands worth hundreds of millions in cryptocurrency, yet the fintech company denies receiving direct contact from any perpetrators.
Competing Claims, Conflicting Demands
A hacking group operating under the name “IAmNotAVillain” has issued a public extortion threat against Revolut, demanding 6,000 Monero—valued at approximately $3 million—and threatening to sell stolen customer records to rival criminal organizations within 24 hours, according to reporting from the Financial Times.
The breach has attracted additional claimants seeking payment. A separate actor identifying as “Revolut Smilik” has demanded 10,000 Bitcoin—valued near $780 million at the time of the demand—in exchange for withholding the data. A third party has surfaced at the domain revoloot.lol, further muddying the circumstances around who actually controls the compromised customer information.
The supposed perpetrators have turned against each other publicly. IAmNotAVillain has published messages on its website disputing “Revolut Smilik’s” legitimacy, alleging that the rival group obtained only a limited data sample through a former associate before falsely claiming responsibility for the entire breach. The organization has warned other parties not to negotiate with the competing claimant, adding to the confusion surrounding the incident’s true scope and actors involved.
Revolut Denies Direct Engagement
Despite the high-profile cryptocurrency ransom threats circulating publicly, Revolut has stated it has not received private communication from any of the groups making demands. “Revolut has not received any direct contact or demand from the individuals or group making these claims,” a company spokesperson told Cointelegraph.
This disconnect between public extortion attempts and the absence of private negotiation raises questions about the sophistication and motives of those claiming responsibility. The development follows Revolut’s disclosure of the breach the prior week.
Italian Government Escalates Investigation
Italian law enforcement has elevated the matter to a national security level, with the National Anti-Mafia and Anti-Terrorism Directorate now investigating the incident, according to Italian news agency ANSA. Authorities are examining how a government email account was allegedly compromised and leveraged to access Revolut’s customer data.
Prosecutors in Reggio Calabria have opened an investigation into unauthorized access to a computer system of national interest, working to determine whether an institutional email account was breached or cloned. Italy’s privacy regulator has independently instructed all banks to conduct urgent reviews of their access control systems and is investigating whether other financial institutions may have been similarly compromised.
The regulatory involvement signals the severity of a breach affecting millions of customers across Europe’s fintech sector, and raises questions about third-party vulnerabilities in financial infrastructure.
Source: Revolut, Financial Times, Italian Authorities, via Cointelegraph. Not financial advice.