discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Revolut says no direct contact after $3 million public ransom demand

Fintech company Revolut denies receiving direct contact despite multiple public ransom demands, including one for $3 million in Monero, following a customer data breach. Italian authorities are now investigating the incident, which allegedly involved a government email ac…

By Helen Partz·Sep 17·cointelegraph.com·4 min read

Intelligence analysis by Gemini 2.5 Flash

Revolut says no direct contact after $3 million public ransom demand
Image: cointelegraph.com

Revolut is grappling with a customer data breach that has led to several public ransom demands, notably one for 6,000 Monero (approximately $3 million) from a group called "IAmNotAVillain" and an earlier claim for 10,000 Bitcoin from "Revolut Smilik." Despite these public ultimatums, Revolut asserts it has not been directly contacted by any claimants, complicating efforts to identify …

Why it matters

This story highlights the complex and often chaotic nature of modern cyberattacks, where companies face not only data breaches but also multiple, potentially competing, ransom demands. It underscores the critical need for robust cybersecurity in the fintech sector and the challenges authorities face in identifying culprits, especially when government systems are implicated.

Imagine a digital piggy bank called Revolut where people keep their money and information. Someone sneaky got inside and copied some of the names and addresses. Now, different groups of bullies are shouting on the internet, saying they have the list and demanding money from Revolut to not share it with other bad guys. But Revolut says no one has talked to them directly, making it confusing who the real bully is. Even the police in Italy are now looking into it because they think one of their own digital mailboxes might have been used to help the sneaky person get in.

Analysis

The recent data breach affecting Revolut has escalated into a convoluted situation, marked by conflicting claims and public ransom demands. Revolut, a prominent fintech firm, has publicly stated that it has not received any direct communication from those claiming responsibility for the customer data compromise, despite several groups making their demands known through public channels. This lack of direct contact adds a layer of uncertainty to an already serious security incident, making it difficult for the company to ascertain the legitimacy or true identity of the actors involved. The situation is further complicated by the involvement of Italian authorities, who are now investigating the alleged use of a government email account in the breach, suggesting a potentially broader and more sophisticated attack vector than initially perceived.

IAmNotAVillain

A group identifying itself as "IAmNotAVillain" has publicly demanded 6,000 Monero (XMR), valued at approximately $3 million, from Revolut. This ultimatum was issued with a strict 24-hour deadline, accompanied by threats to sell the compromised customer records to other criminal entities if the demand was not met. The group's website, iamnotavillain.xyz, was reportedly unavailable at the time of Cointelegraph's publication, adding to the ambiguity surrounding their operations and current status. Their public declaration and specific monetary demand in a privacy-focused cryptocurrency like Monero indicate a calculated attempt to pressure Revolut while maintaining a degree of anonymity.

IAmNotAVillain also actively disputed claims from a rival group, alleging that a former associate had only a small sample of the data and was falsely taking credit for the entire breach. This internal conflict among alleged perpetrators further muddies the waters for Revolut and investigators, making it challenging to determine who genuinely possesses the stolen data and who is merely attempting to capitalize on the incident. The public warning against dealing with the rival claimant underscores the competitive and fragmented nature of the cybercrime landscape.

Revolut Smilik

Prior to the demands made by IAmNotAVillain, another group operating under the name "Revolut Smilik" reportedly issued a significantly larger ransom demand. This group sought 10,000 Bitcoin, which at the time of their claim was estimated to be worth around $780 million. The vast disparity between this demand and the subsequent $3 million Monero request highlights the chaotic and uncoordinated nature of the ransom attempts. Such a substantial difference in demanded amounts could indicate varying levels of access to the stolen data, different motivations, or simply opportunistic attempts by unrelated parties.

The existence of multiple claimants, including a third actor associated with the website revoloot.lol flagged by Dark Web Informer, suggests a fragmented landscape of individuals or groups attempting to profit from the Revolut data breach. This fragmentation makes it exceedingly difficult for Revolut to verify the authenticity of any single demand or to engage in negotiations, even if they were inclined to do so. The competing claims and public disputes among these groups create a complex challenge for both the affected company and law enforcement agencies trying to unravel the incident.

Italian authorities

Italian authorities have significantly escalated their involvement in the Revolut data breach investigation, with the National Anti-Mafia and Anti-Terrorism Directorate now participating. This heightened level of scrutiny stems from the suspected intrusion concerning a government entity, specifically an alleged compromise of an institutional email account used to obtain customer data. Prosecutors in Reggio Calabria have initiated an investigation into unauthorized access to a computer system of public interest, indicating the serious nature of the breach and its potential implications beyond just Revolut's customers.

Investigators are actively working to determine whether the government email account was directly breached or merely cloned, a distinction that could significantly impact the scope and direction of the ongoing probe. Italy's privacy regulator has also taken action, urging banks to urgently review the security of their access systems and examining whether other financial institutions might have been affected. This broad regulatory response underscores the potential systemic risks posed by such a breach, particularly if it exploited vulnerabilities within public infrastructure or affected multiple financial entities.

Key points

  • Revolut denies direct contact despite multiple public ransom demands following a customer data breach.
  • A group named "IAmNotAVillain" publicly demanded 6,000 Monero (approx. $3 million) within 24 hours.
  • An earlier group, "Revolut Smilik," reportedly demanded 10,000 Bitcoin (approx. $780 million).
  • Italian authorities, including the National Anti-Mafia and Anti-Terrorism Directorate, are investigating the breach.
  • The probe focuses on whether a government email account was breached or cloned to obtain customer data.
The Upside

Revolut's assertion of no direct contact could indicate a strategy to avoid legitimizing the ransom demands, potentially allowing them to focus on strengthening security and cooperating with law enforcement. If Italian authorities successfully identify and apprehend the perpetrators, it could lead to the recovery or secure handling of the stolen data, mitigating the long-term impact on customers and deterring future attacks.

The Downside

The presence of multiple, unverified ransom demands creates significant uncertainty, increasing the risk that stolen customer data could be sold to various criminal groups if Revolut does not comply or if the true perpetrators remain unidentified. This chaotic situation could severely damage Revolut's reputation and customer trust, potentially leading to substantial regulatory fines and a loss of market share.

Originally reported at

cointelegraph.com

Discernion covers the story. Read the full piece at the source.

Tagscryptosecuritydata-breachransomwarefintechmonerobitcoinitalyregulation

Author

Helen Partz

Intelligence analysis by

Gemini 2.5 Flash

Published

Sep 17, 2026

Source

cointelegraph.com

Share

Topics

cryptosecuritydata-breachransomwarefintechmonerobitcoinitalyregulation

Related

More from this desk

Oct 7·cointelegraph.com

Sui offchain network hits 40.6M TPS in live AI agent test

Sui's offchain tunnels process over 40 million transactions per second in a live stress test, surpassing a previous record.

money bitcoin Breaking Push cryptocurrency crime U.S. government strategic Bitcoin reserve bitcoin seizure
Oct 7·decrypt.co

US Government Moves $103 Million in Seized Bitcoin and BNB, But Hasn't Said Why

US Government moves $103 million in seized Bitcoin and BNB, details unclear.

Gate bets all-in-one money app is crypto’s biggest consumer trend this year and next

Oct 7·coindesk.com

Gate bets all-in-one money app is crypto’s biggest consumer trend this year and next

Gate is expanding its services to include a new app that combines accounts, asset conversion, savings, and card payments, targeting mainstream consumers, particularly in Asia.

Oct 7·cointelegraph.com

World Liberty Financial Plans USD1 Payments for Online Businesses

World Liberty Financial unveils plans to bring USD1 stablecoin payments to major online businesses, partnering with Mesh.