TTO-2026-0917-133 · September 17, 2026 ExtortionData Breach

Revolut Extortion Demand: iamnotavillain Group Demands 6,000 XMR for 680 Customer Records Including Passports and Crypto Transaction Histories

revolut.comiamnotavillain group6,000 XMR (~$3M) demand24-hour deadline680 accountsPassports / KYC photos / crypto transaction historiesFake Italian government emailUK ICO investigating

Summary

A threat group calling itself iamnotavillain has issued a public extortion demand against Revolut, the UK-based fintech and digital bank, demanding 6,000 Monero (approximately $3 million) within 24 hours in exchange for not selling stolen customer records to other criminal organizations. The group claims to hold records from at least 680 Revolut customer accounts, reportedly including passports, driving licences, photographs submitted during know-your-customer identity checks, and complete cryptocurrency transaction histories. The breach occurred after attackers submitted fraudulent information requests that passed Revolut’s verification checks by posing as Italian government officials using what appeared to be a legitimate Italian government email address. Revolut has confirmed the incident, said customer funds are safe, and stated it has informed law enforcement. The UK Information Commissioner’s Office has opened an investigation.

Timeline

DateEvent
Prior to Sep 2026Attackers pose as Italian government officials using a real Italian government email address; Revolut processes fraudulent customer information requests before discovering the fraud
Sep 16, 2026iamnotavillain posts public extortion demand with countdown clock; demands 6,000 XMR (~$3M) within 24 hours; provides Financial Times with 60-second screen recording showing sample data
Sep 16, 2026Financial Times reports the demand; Reuters separately reports Revolut received no direct ransom contact — accounts differ on whether Revolut was directly contacted
Sep 17, 2026UK Information Commissioner’s Office confirms investigation; Revolut says customer funds safe and matter reported to law enforcement

What Happened

The attack exploited Revolut’s legal information-sharing process rather than its technical infrastructure. Attackers obtained or compromised a legitimate Italian government email address and submitted official-looking requests for customer information that Revolut’s compliance processes were designed to fulfill. The requests passed verification and Revolut handed over customer records before the fraudulent nature was discovered.

The 680 affected accounts were not selected at random. The hackers told the Financial Times they used blockchain analysis to identify Revolut customers who appeared to hold substantial cryptocurrency assets. The stolen data therefore connects visible on-chain wealth to real-world identities, creating risk beyond standard identity theft: a home address, a passport photo, and a documented history of large cryptocurrency holdings is exactly the profile that enables targeted physical attacks against crypto holders.

Revolut described the number of affected accounts as a “very limited” portion of its customer base and distinguished between KYC photographs and biometric facial telemetry data, stating the latter was not exposed. Private keys, passwords, security codes, and complete payment card details were also not among the exposed information. The earlier demand of 10,000 Bitcoin circulated on Telegram was attributed by the group to an impersonator — the confirmed demand is 6,000 XMR.

Domain Intelligence

revolut.com — 60.92

revolut.com scores at 60.92, in the low-trust range, with T5_NO_CORPUS_HITS and T5_WEAK_CLUSTER flags. T5_NO_CORPUS_HITS means the topology layer found zero corpus observations for revolut.com at time of scoring — the score is produced entirely from T6 signals. This bulletin is published at operator discretion given the significance of the active extortion event.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 17, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026