Italian prosecutors have opened an investigation after criminals allegedly used a compromised government email account to obtain information about hundreds of Revolut customers. The attackers demanded 6,000 Monero (XMR) in ransom and set a 24-hour deadline on September 16, threatening to sell sensitive customer records to criminals if the payment was not made.
At least 680 customer accounts were compromised in the incident. The attackers, identifying themselves as "iamnotavillain," provided evidence including passports, driving licenses, identity photographs, and transaction histories from affected customers.
How the breach occurred
According to reports, the attackers used blockchain analysis to identify customers with significant cryptocurrency holdings. They then obtained customer records by compromising an Italian government email system and impersonating law enforcement officials.
Revolut's response
Revolut stated it had not formally heard from the group and received no ransom demands. The company confirmed that none of its internal systems or client funds had been breached or affected. Revolut said it was working closely with regulators and law enforcement to support affected customers.
Investigation underway
Italian prosecutors and the country's anti-mafia and counterterrorism authorities are now investigating the incident.
Why Monero was demanded
Monero hides transaction amounts and the identities of senders and recipients, offering financial privacy protections that appeal to criminals seeking to conceal ransoms. The use of XMR for payment does not imply the Monero network itself was breached or involved in obtaining the customer records.
It remains unclear whether payment was made after the ransom deadline passed or whether the data was subsequently sold as threatened.


