Revolut Data Breach Hackers Demand $3 Million in Monero

by · Blockonomi

TLDR

Table of Contents

Toggle

  • Hackers claim they used a compromised Italian government email system to pose as law enforcement and pull Revolut customer data.
  • The group, calling itself iamnotavillain, says it holds files on 680 Revolut customers spread across 31 countries.
  • The hackers first asked for bitcoin, then switched their demand to 6,000 monero, worth about $3 million.
  • Revolut says its own systems and customer funds were not touched, and it has blocked the fraudulent channel.
  • Italian officials are investigating how the government’s PEC email system was used to pull off the scheme.

A hacking group says it tricked Revolut into handing over customer data by pretending to be Italian law enforcement. The group is now demanding 6,000 monero, worth roughly $3 million, to keep the files private.

The group calls itself iamnotavillain. It says it first reached out to Revolut a couple of months ago, claiming to represent an Italian law enforcement agency.

The messages reportedly went through Italy’s La Posta Elettronica Certificata system, known as PEC. This is a certified email network used by Italian government offices, companies, and citizens for official communication.

How the Scheme Worked

Because the emails came through a real government channel, they carried valid domain authentication. Revolut had no easy way to confirm the sender wasn’t actually an authorized official.

Over several weeks, the hackers say they repeatedly asked Revolut for account details tied to specific customers. Revolut allegedly complied, sharing names, addresses, phone numbers, and transaction histories.

The targets were not chosen randomly. The group says it used onchain analysis to find Revolut users with large crypto holdings, describing them as “whales.”

According to reporting from the Financial Times, 680 customer accounts were affected. Most of those customers are based in Switzerland and France, though people in 31 other countries were also impacted, including the UK, Germany, and Spain.

The data allegedly obtained includes passports, selfies used for identity checks, account IDs, and records of crypto deposits and withdrawals. Fiat transfers were reportedly included too.

The Ransom Demand

The hackers first floated a demand for 10,000 bitcoin on Telegram. They later said that figure came from an impersonator, not the group itself.

On September 16, iamnotavillain posted a new demand on a website using the group’s name. It asked for 6,000 monero within 24 hours, or the files would be sold to other criminal groups.

Monero is a cryptocurrency built to hide transaction details, unlike bitcoin, which is traceable on a public ledger. That makes it a common choice for extortion demands.

Revolut has said it had not received a direct ransom demand from the group as of when the countdown appeared. The company says its core systems, databases, and customer funds were never breached.

In a statement, Revolut said the incident involved “the fraudulent misuse of an official, state-regulated legal communication channel to impersonate legitimate authority requests.” The company says it identified the scam, blocked the address involved, and notified law enforcement and regulators.

Italian officials, including postal police and the interior ministry, have confirmed an investigation is underway but declined further comment. Opposition lawmaker Giulia Pastorella called the breach of a government email account “alarming” and said she plans to raise the issue in parliament.

Revolut first disclosed the incident on September 12. The investigation into how the government email system was compromised is still ongoing.

Advertise Here