Revolut Says It Has Received No Direct Contact Amid Multiple Ransom Demands Over Data Breach
Key Takeaways
- •Revolut stated it has received no direct contact or ransom demand from any individual or group claiming responsibility for the customer data breach.
- •A group calling itself IAmNotAVillain publicly demanded 6,000 Monero, valued at roughly3 million, within 24 hours and threatened to sell the stolen customer records to other criminal groups.
- •Multiple actors have claimed involvement, including a group reportedly known as Revolut Smilik, which demanded 10,000 Bitcoin, leaving uncertainty over who controls the stolen data.
- •Italy's National Anti-Mafia and Anti-Terrorism Directorate joined the probe, and prosecutors in Reggio Calabria opened an investigation into unauthorized access involving a government email account allegedly used to obtain customer data.
- •Italy's privacy regulator has asked banks to urgently review the security of their access systems and is examining whether other banks or financial institutions may have been involved.

Revolut said Thursday that it has received no direct contact from anyone claiming responsibility for a customer data breach, despite multiple public ransom demands.
A group calling itself “IAmNotAVillain” publicly demanded 6,000 Monero (XMR), worth about $3 million, from the fintech firm within 24 hours, threatening to sell the customer records to other criminal groups, the Financial Times reported on Wednesday.
“Revolut has not received any direct contact or demand from the individuals or group making these claims,” a Revolut spokesperson told Cointelegraph.
The public ultimatum is the latest development in a data breach that Revolut first disclosed last week, with Italian authorities now widening their investigation into how a government email account was allegedly used to obtain customer data.
One breach, multiple ransom demands
Revolut’s statement that it has received no direct contact adds to uncertainty over who is behind the public ransom demand, as “IAmNotAVillain” is not the only name linked to claims of responsibility for the incident. The group’s website, iamnotavillain.xyz, was unavailable when checked by Cointelegraph at the time of publication.
An earlier group calling itself “Revolut Smilik” reportedly demanded 10,000 Bitcoin (BTC), worth about $780 million at the time — vastly more than IAmNotAVillain’s current $3 million Monero demand.
IAmNotAVillain disputed the competing claim in a notice on its website, alleging that a former associate had received only a small sample of the data before taking credit for the breach. The site also warned others not to deal with the rival claimant.
Cybersecurity-focused account Dark Web Informer separately flagged another website, revoloot.lol, associated with a distinct actor claiming responsibility, further complicating efforts to establish who controls the stolen customer records. That website was also unavailable when checked by Cointele.
Italian authorities widen Revolut data breach probe
Italy’s National Anti-Mafia and Anti-Terrorism Directorate is also now involved because the suspected intrusion concerns a government entity, Italian news agency ANSA reported on Wednesday.
Prosecutors in Reggio Calabria have opened an investigation into unauthorized access to a computer system of public interest, while investigators work to establish whether the institutional email account was breached or cloned.
Italy’s privacy regulator has separately asked banks to urgently review the security of their access systems and is examining whether other banks or financial institutions may have been involved.