Revolut says no direct contact from hackers after $3M public ransom demand
Revolut said it has not received any direct contact from individuals or groups claiming responsibility for a recent customer data breach, despite public ransom demands posted online. Competing claimants have publicly asked for 6,000 Monero (about $3 million) and, in a separate post, 10,000 Bitcoin (roughly $780 million), while Italian authorities have broadened an investigation tied to an allegedly compromised government email account.

Why It Matters
Multiple, conflicting public extortion demands and lack of direct contact increase uncertainty about who controls the stolen data and whether the claims are credible. At the same time, involvement of Italian prosecutors and anti-mafia/anti-terrorism authorities highlights potential cross-border and institutional implications of the incident.
Key Facts
- Revolut statement: Revolut said it received no direct contact or demand from those claiming responsibility.
- Monero ransom demand: A group calling itself 'IAmNotAVillain' publicly demanded 6,000 Monero (about $3 million).
- Bitcoin ransom demand: An earlier claimant using the name 'Revolut Smilik' reportedly demanded 10,000 Bitcoin (about $780 million).
- Website availability: iamnotavillain.xyz and revoloot.lol were unavailable when checked by Cointelegraph.
- Italian investigation: Italy's National Anti-Mafia and Anti-Terrorism Directorate and prosecutors in Reggio Calabria have opened or widened probes tied to a suspected government email account used to obtain customer data.
Revolut has told reporters it has not had any direct contact with individuals or groups claiming responsibility for a disclosed customer data breach, even though multiple public ransom demands have appeared online. One group calling itself IAmNotAVillain publicly posted an ultimatum demanding 6,000 Monero, which Cointelegraph cited as roughly $3 million, while an earlier claimant using the name Revolut Smilik asserted control and demanded 10,000 Bitcoin — a sum reported to be in the hundreds of millions of dollars.
The competing public claims and Revolut's statement that it has received no direct approaches have left uncertainty about who actually possesses the stolen records. IAmNotAVillain has disputed credit taken by the earlier claimant, asserting on its site that a former associate held only a small sample of the data and warning others not to engage with that rival. Cybersecurity observers also flagged an additional site, revoloot.lol, tied to a separate actor; Cointelegraph reported that the cited sites were unreachable at the time of checking.
Italian authorities have expanded their work into the matter because the apparent intrusion involves a government email account. Italy's National Anti-Mafia and Anti-Terrorism Directorate is now involved, and prosecutors in Reggio Calabria have opened an investigation into unauthorized access to a computer system of public interest. Investigators are working to determine whether the institutional email was breached or cloned, and the country's privacy regulator has asked banks to urgently review access security and to assess whether other financial institutions may be affected.
The public, conflicting extortion demands and the involvement of multiple investigative bodies underline challenges investigators face in attributing responsibility and assessing the scope of the incident. Revolut first disclosed the breach last week, and authorities and affected parties continue to probe how the data were obtained and who may hold or be attempting to monetize the records.
Keep Reading

Comp AI sets eyes on a continuously agentic future for security and compliance

OpenAI discloses 6 new cases of ‘misaligned’ AI behavior

Former Waymo CFO jumps to self-driving startup Wayve
