Revolut says it has received no direct contact after a $3 million public ransom demand
Revolut says the people claiming responsibility for a customer data breach have not contacted it directly, even as multiple groups publicly escalate ransom demands. For PSPs and banks, the useful detail is not the spectacle; it is the signal that a breach can turn into a messy attribution problem fast, while regulators start asking who accessed what and through which system.
- A group calling itself IAmNotAVillain publicly demanded 6,000 Monero (XMR), worth about $3 million, from Revolut within 24 hours, and threatened to sell the customer records to other criminal groups, the Financial Times reported Wednesday.
- Revolut said, via a spokesperson quoted by Cointelegraph, that it “has not received any direct contact or demand from the individuals or group making these claims.” That leaves the public ransom note standing on its own, which is not exactly a reassuring place for a breach response to be.
- The demand follows a data breach Revolut first disclosed last week. Italian authorities are now widening their investigation into how a government email account was allegedly used to obtain customer data.
- The attribution issue is still muddy. An earlier group calling itself Revolut Smilik reportedly demanded 10,000 Bitcoin, worth about $780 million at the time, while IAmNotAVillain disputed that claim and said a former associate had only received a small sample of the data before taking credit for the breach.
- Cybersecurity-focused account Dark Web Informer also flagged another site, revoloot.lol, tied to a separate actor claiming responsibility. Both that site and iamnotavillain.xyz were unavailable when checked by Cointelegraph, which does little to clarify who actually controls the stolen records.
Italy’s National Anti-Mafia and Anti-Terrorism Directorate is involved because the suspected intrusion concerns a government entity. Prosecutors in Reggio Calabria have opened an investigation into unauthorized access to a computer system of public interest, while Italy’s privacy regulator has asked banks to urgently review the security of their access systems and is checking whether other banks or financial institutions may have been involved.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!