Newsroom
17 September, 2026 / News / AI / Tags: revolut, italian, email, group, monero

A group calling itself iamnotavillain has set a 24-hour deadline for payment in privacy-focused cryptocurrency or it will offer the files to other criminals
A cybercriminal group identifying as iamnotavillain has publicly demanded 6,000 monero, valued at approximately $3 million, from Revolut within 24 hours. The demand, posted on the group’s website alongside a countdown clock on September 16, 2026, comes with a threat to sell sensitive records belonging to about 680 customers to other criminal organizations if the payment is not made.
Revolut has stated that it has received no direct contact or formal demand from the group. The company previously described the underlying incident as a sophisticated external impersonation scam and confirmed that its systems and customer funds remain unaffected.
According to accounts provided by the group to journalists, the attackers did not breach Revolut’s internal networks. Instead, they posed as Italian law enforcement officials and submitted formal information requests over a period of several months. The messages were sent through Italy’s Posta Elettronica Certificata system, a certified email network used for official and legal communications, and carried valid domain authentication credentials linked to a government agency.
Revolut treated the requests as legitimate and supplied the requested customer files. Once the company identified the fraud, it blocked the email address involved and notified the relevant government agency, law enforcement, data-protection authorities and financial regulators. The disclosure to affected customers and regulators occurred around September 12.
Italian prosecutors in Reggio Calabria have opened an inquiry into possible unauthorized access to a prefecture’s certified email account. The account is reported to have been used to send fraudulent requests appearing to come from the postal police or an interior ministry domain. Italy’s national anti-mafia and anti-terrorism prosecutors are monitoring the matter, and the country’s data protection authority has contacted its Lithuanian counterpart, given Revolut’s legal headquarters in Lithuania.
The group claims to hold detailed records on roughly 680 individuals. The material reportedly includes full names, dates of birth, home addresses, email addresses, telephone numbers, International Bank Account Numbers, account-opening dates, passports or driving licences, verification selfies submitted during know-your-customer checks, and complete transaction histories. Some records also contain Bitcoin wallet references and related cryptocurrency activity.
Revolut has said that private keys, passwords, security codes, complete payment-card details and biometric facial telemetry data beyond the selfies were not among the disclosed information. The company has characterized the number of affected accounts as a very limited portion of its overall customer base.
The attackers stated that they selected targets through on-chain analysis to identify Revolut users with substantial cryptocurrency holdings, referring to them as crypto whales. Most of the affected customers are said to be based in Switzerland and France, with others located across 31 countries including the United Kingdom, Germany and Spain.
An earlier demand circulating on Telegram called for 10,000 bitcoin. The group later attributed that figure to an impersonator or former associate and switched the request to monero. The privacy-focused cryptocurrency was chosen because its design conceals transaction details, including sender, recipient and amount.
The group provided journalists with a 60-second screen recording that appeared to display portions of the material in its possession, including identity documents and transaction records. It has also claimed to hold 147 gigabytes of data that includes Italian police documents, an assertion now under investigation by Italian authorities.
Britain’s Information Commissioner’s Office has confirmed receipt of a report from Revolut and is assessing the situation. The Financial Conduct Authority is working with the company to evaluate the scope of the incident and any potential risks to customers. Authorities in Italy continue to examine how the certified email channel was used.
Revolut has maintained that the incident resulted from fraudulent external requests rather than a compromise of its core infrastructure. The company has advised customers to remain vigilant against social engineering attempts that may exploit the exposed personal and transactional details.









