Revolut is being investigated after hackers calling themselves "iamnotavillain" claimed to have about 147GB of customer files and demanded $3m (6,000 XMR) in Monero. Revolut says roughly 680 European customers had personal data exposed but that customer funds were not accessed. Italian prosecutors, national cybercrime police and the Anti-Mafia directorate are probing the incident while Italian and Lithuanian data protection authorities coordinate checks.
Revolut Blackmail: Hackers Claim 147GB of Customer Data, Demand $3M in Monero

Revolut is under investigation after a group of hackers claiming the name "iamnotavillain" said they hold roughly 147 gigabytes of customer files and demanded $3,000,000 (6,000 XMR) in Monero. Italian prosecutors in Reggio Calabria and national cybercrime authorities are probing how attackers used a compromised or cloned institutional email linked to a public body to request sensitive data.
What Happened
According to reports, the attackers posted a ransom demand on a dark web site and told the Financial Times via Telegram that they would sell the stolen data to other criminal organisations if payment was not received within 24 hours. Revolut has confirmed that personal data belonging to about 680 European customers were affected but said customer funds were not accessed.
Claims and Evidence
The extortion message quoted by the newspaper read: "6,000 XMR / 3,000,000 $… otherwise all the data will be sold and you will have blood on your hands." The group provided a 60-second screen recording to the Financial Times showing an unidentified user scrolling through documents the attackers say belong to Revolut. The alleged haul includes passport details, driving licence information, other identity documents and photographs.
Investigation and Authorities
Prosecutors in Reggio Calabria are examining the case and considering charges related to intrusion into an IT system of public interest. Italy's cybercrime police describe the operation as technically sophisticated and say it may have been ongoing for months. The National Anti-Mafia and Counter-Terrorism Directorate is also involved because the attack used a government-linked email address.
Investigators are still determining whether the compromise originated from a computer at the Reggio Calabria prefecture, a terminal at Italy's Interior Ministry, or whether the institutional email was cloned rather than directly infiltrated.
Regulatory Response
Italy's data protection authority has initiated checks for possible security weaknesses across Italian banks and urged data-protection officers to perform immediate reviews and report vulnerabilities. The Italian regulator has opened information channels with its Lithuanian counterpart—where Revolut is registered—to coordinate responses and information exchanges.
What This Means For Customers
Revolut customers affected by the breach should watch for official communications from the company and follow guidance on identity protection. Although Revolut says customer funds remain secure, customers whose personal documents were exposed should consider monitoring credit, enabling identity alerts, and reporting suspicious activity.
Next steps: Authorities will determine how the intrusion occurred, whether other public bodies were affected, and whether the data the attackers claim to hold are authentic and complete.
Help us improve.




























