A hacker group identifying itself as "iamnotavillain" has demanded 6,000 XMR, roughly $3 million, from Revolut, claiming to hold personal data on 680 of the fintech's customers. The group set a 24-hour ultimatum on Wednesday, September 16, threatening to publish the material unless paid in Monero, a privacy-focused cryptocurrency.

According to Revolut, the data was not obtained through a breach of its own systems. Instead, the company says the material was delivered via a hijacked certified email account, known in Italy as a PEC, belonging to the Prefecture of Reggio Calabria. The prefecture has denied sending any such request. The mechanism described mirrors an Emergency Data Request, a legal tool normally used by law enforcement to obtain user information quickly from companies in urgent cases.

Revolut says the exfiltrated material includes passports, driving licenses, KYC photographs and transaction histories. The bulk of the affected clients are based in Switzerland and France, with the remainder spread across 31 other European countries, including the United Kingdom, Germany and Spain. Revolut states it serves more than 80 million customers globally, meaning the 680 affected accounts represent a small fraction of its user base.

A Pattern of Fraudulent Requests

The Italian cybersecurity agency CERT-AGID has recorded more than 650 incidents linked to hijacked or fraudulently created PEC accounts since the start of the year, suggesting the method used against Revolut is not an isolated tactic.

The iamnotavillain ransom claim follows an earlier, separate demand reported by the Financial Times, in which an actor calling itself "Revolut Smilik" sought 10,000 BTC, then worth over $780 million, from the company. iamnotavillain has dismissed that earlier claim as fraudulent, saying it was based on nothing more than a simple data sample.

Revolut says no theft of funds has occurred and it has not announced any ransom payment.

Monero's Role and Prior Incidents

The choice of Monero for the ransom demand is notable given the currency's declining accessibility on major exchanges. Binance delisted Monero in 2024, and Kraken subsequently restricted the asset for European users.

Extortion attempts against crypto-linked firms have grown more frequent. Coinbase disclosed in May 2025 that contractors had been bribed from abroad to leak data belonging to nearly 70,000 users, accompanied by a $20 million ransom demand in bitcoin. Chief executive Brian Armstrong refused to pay, instead redirecting the sum into a reward for information leading to the arrest of those responsible. Coinbase has estimated remediation costs at between $180 million and $400 million.

Ledger suffered a data breach in 2020, and the risks extend beyond digital theft: cofounder David Balland was held captive before being freed by France's GIGN in January 2025.