Hackers have made a public ransom demand following a breach at British neobank Revolut, requesting approximately $3 million in Monero (XMR), a privacy-focused cryptocurrency. The group, identifying itself as 'iamnotavillain,' issued the demand on Wednesday, September 16, with a stated 24-hour deadline to begin selling the stolen personal information.
The attack compromised data belonging to 680 European customers. Revolut confirmed that customer funds remained untouched but initially withheld details about the breach method, describing it as "a sophisticated external impersonation scam" involving an unauthorized email sent from a genuine government domain.
Investigations later revealed that attackers used a domain belonging to the Reggio Calabria prefecture in southern Italy. The regional public prosecutor's office opened an inquiry into the incident, with support from Lithuanian authorities.
Exposed Data
According to blockchain investigator ZachXBT, the attackers appeared to target high-net-worth neobank clients. The compromised information included:
- Copies of passports and/or driver's licenses plus verification selfies
- Account statements, IBAN numbers, withdrawal records, and full transaction history including Bitcoin holdings
- Full names, dates of birth, and occupations
- Home addresses, email addresses, and phone numbers
The public ransom demand was noted as unusual for extortion attempts. The demand also appeared to contradict earlier reports suggesting attackers had sought 10,000 Bitcoin as compensation.


