Key Takeaways
- Revolut reportedly sent records on 680 users after criminals posed as officials through a real Italian email system.
- The hacking syndicate dubbed Iamnotavillain demanded 6,000 monero (XMR), about $3 million, after obtaining Revolut customer files. Initially, the hackers demanded BTC.
- Revolut disclosed the scam Sept. 12 as investigators examine how the government email channel was abused.
According to the hackers speaking exclusively with the Financial Times (FT), Revolut didn’t lose customer data because hackers cracked its servers. The attackers simply asked for it. Posing as Italian law enforcement for months and using a legitimate government email system, a crew calling itself iamnotavillain spent months requesting files on specific cryptocurrency users.
The hackers’ claims were made to FT reporters Tom Wilson, Laith Al-Khalaf, and Amy Kazmin over “a series of messages.” Revolut allegedly complied with the requests, sending records that included passports, selfies, and transaction histories. Now the group says it has data on about 680 people and wants 6,000 monero (XMR), roughly $3 million, while a public countdown clock threatens to turn those identity files over to other criminals.
They Didn’t Break In. They Asked
The Revolut data breach reportedly worked because the attackers allegedly used Italy’s Posta Elettronica Certificata, or PEC, system, a certified-email network used for legal and government communications. Messages sent through the compromised channel carried genuine domain authentication credentials, so Revolut saw mail that appeared to come from a real government authority.
That was the catch. Authentication could show that an email came from the legitimate domain, but it could not prove the person behind the account was actually an authorized official. Instead of beating Revolut’s security systems, the attackers claim to have exploited the process designed to handle lawful government requests.
The Victims Were Chosen First
This was not a random data grab. The group claims it used onchain analysis to identify Revolut users with substantial cryptocurrency activity, then requested records on those people by name. FT’s reporting cited the affected group at about 680 people who leveraged the platform across 31 countries, with many in Switzerland and France.
The files allegedly included names, addresses, phone numbers, account IDs, crypto deposits and withdrawals, fiat transfers, KYC documents, and verification selfies. In plain English, the crew was not collecting basic contact information. It was building detailed identity packages on people it believed were worth targeting.
Then Came the Monero Demand
On Sept. 16, Iamnotavillain posted a public ultimatum on a website with that very name, demanding 6,000 XMR, framed as roughly $3 million, within 24 hours or the stolen files would be sold to other criminal groups. An earlier 10,000 bitcoin (BTC) demand circulated on Telegram, but the crew later blamed that figure on an impersonator or former associate.
To many observers, the switch to monero (XMR) makes sense for an extortion demand. Bitcoin transactions are visible on a public ledger, while XMR is designed to obscure transaction details. Revolut, meanwhile, told the press that it had received no direct demand from the people claiming responsibility when the countdown appeared, making the clock as much a public pressure campaign as a negotiation.
Revolut maintains that its systems and customer funds were unaffected. The criminals apparently did not penetrate the company’s core network or drain customer accounts. The claim at hand is that they reportedly persuaded Revolut to hand over information through what looked like legitimate official requests.
That does not make the stolen records harmless. A passport, selfie, home address, phone number, and transaction history can support impersonation, account resets, fake support calls, and follow-on attacks against other financial services. The real danger is not only what was taken from Revolut, but what those files could unlock elsewhere.
The Bigger Problem Is the KYC Trust Channel
Revolut told Techcrunch on Sept. 12 that it had identified the impersonation scam, blocked the address, and notified the relevant agency, law enforcement, and regulators. Investigators are now examining how a legitimate government communications channel became part of the operation.
That leaves an uncomfortable question beyond the digital currency firm itself. If one compromised government mailbox could generate months of convincing information requests, other crypto institutions may have received similar messages. The attackers did not crack the vault. They made themselves look like the people legally allowed to ask for it to be opened.







